Apache Software Foundation has 91 CVEs on record. Disclosure cadence is accelerating: 90 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 88. The median CVSS is 7.5 (high), with 28 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (11) and CWE-79 (6). Most affected products: Apache Tomcat (12), org.apache.storm:storm-server (8), Apache Sling XSS (5).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 90 prev 1
Weakness classes
Products
- Apache Tomcat 12
- org.apache.storm:storm-server 8
- Apache Sling XSS 5
- Apache Doris 4
- org.apache.syncope.core:syncope-core-provisioning-java 4
- org.apache.syncope.core:syncope-core-spring 4
91
Total CVEs
28
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-86350Critical· 9.1Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: fr…62CVE-2026-92609Critical· 9.8Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affect…54CVE-2026-86248Critical· 9.8CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9…54CVE-2026-82331Critical· 9.8Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of th…54CVE-2026-76183Critical· 9.8Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 throug…54
Apache Software Foundation vulnerabilities
CVEs affecting Apache Software Foundation, newest first. Open any entry for full detail, references, and exploit status.
91 CVEsRSS