Apache has 188 CVEs on record. Cadence is steady at roughly 82 per quarter. The busiest recent month was September 2026 with 46. The median CVSS is 7.5 (high), with 34 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1633 days (7 cases). The dominant weakness classes are CWE-502 (18) and CWE-200 (11). Most affected products: airflow (21), tomcat (21), cxf (11).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 4% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- 1633 d median(7)
- Last 90 days
- 82 prev 63
Weakness classes
Products
- airflow 21
- tomcat 21
- cxf 11
- thrift 9
- artemis 8
- http_server 8
Worst active — by depth score
CVE-2021-44228Critical· 10.0Log4Shell: JNDI RCE in Apache Log4j 2100CVE-2020-1938Critical· 9.8When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat99CVE-2016-8735Critical· 9.8Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports97CVE-2017-12615High· 8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g94CVE-2017-12617High· 8.1When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g90
Apache vulnerabilities
CVEs affecting Apache, newest first. Open any entry for full detail, references, and exploit status.
188 CVEsRSS
CVE-2026-44914High· 7.2Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additio…
CVE-2026-54665Medium· 5.3Apache NiFi fails to validate proxy host headers when constructing qualified URLs
Apache NiFi fails to validate proxy host headers when constructing qualified URLs
CVE-2026-44911LowApache NiFi allows read-only users to submit component configuration verification request
Apache NiFi allows read-only users to submit component configuration verification request
CVE-2026-32966Critical· 9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967Critical· 9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVE-2026-41280Medium· 4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CVE-2026-42357Medium· 6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
CVE-2026-47340Medium· 6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
CVE-2026-49268HighPoCApache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
CVE-2026-50645High· 7.5There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upg…
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upg…
CVE-2026-50634Medium· 6.5A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Ty…
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Ty…
CVE-2026-50633High· 8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …
CVE-2026-50632High· 8.1A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
CVE-2026-50631High· 7.4A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh…
CVE-2026-50630Medium· 6.5A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) charac…
CVE-2026-50629Medium· 5.3The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries,…
CVE-2026-50628Critical· 9.8A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security c…
CVE-2026-50627Critical· 9.1The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Reso…
CVE-2026-50623Medium· 4.8An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed…
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed…
CVE-2026-49875Critical· 9.8⚖ disputedApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…
CVE-2026-25700High· 7.2Apache Answer: AdminToken not invalidated after admin deactivation
Apache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-34031Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-33582Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-34905Medium· 6.5Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-34033Medium· 5.4Apache Answer vulnerable to Cross-site Scripting
Apache Answer vulnerable to Cross-site Scripting
CVE-2026-25699Medium· 6.1Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
CVE-2026-25688Medium· 6.1Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
CVE-2026-44185High· 7.3Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…
CVE-2026-42536High· 7.5PoCHeap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…
CVE-2026-34355High· 7.5A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.