Apache has 188 CVEs on record. Cadence is steady at roughly 82 per quarter. The busiest recent month was September 2026 with 46. The median CVSS is 7.5 (high), with 34 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1633 days (7 cases). The dominant weakness classes are CWE-502 (18) and CWE-200 (11). Most affected products: airflow (21), tomcat (21), cxf (11).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 4% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- 1633 d median(7)
- Last 90 days
- 82 prev 63
Weakness classes
Products
- airflow 21
- tomcat 21
- cxf 11
- thrift 9
- artemis 8
- http_server 8
Worst active — by depth score
CVE-2021-44228Critical· 10.0Log4Shell: JNDI RCE in Apache Log4j 2100CVE-2020-1938Critical· 9.8When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat99CVE-2016-8735Critical· 9.8Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports97CVE-2017-12615High· 8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g94CVE-2017-12617High· 8.1When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g90
Apache vulnerabilities
CVEs affecting Apache, newest first. Open any entry for full detail, references, and exploit status.
188 CVEsRSS
CVE-2020-9484High· 7.0PoCWhen using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
CVE-2020-1938Critical· 9.8CISA KEVPoCWhen using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections ar…
CVE-2019-17569Medium· 4.8The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a pos…
CVE-2019-10086High· 7.3In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using…
CVE-2017-12617High· 8.1CISA KEVPoCWhen running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possib…
CVE-2017-12615High· 8.1CISA KEVPoCWhen running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted requ…
CVE-2016-8735Critical· 9.8CISA KEVRemote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue e…
CVE-2021-44228Critical· 10.0CISA KEV0dayPoCLog4Shell: JNDI RCE in Apache Log4j 2
Log4j 2 evaluates ${jndi:...} lookups in logged strings, allowing an attacker who controls any logged value to load and execute remote code via LDAP/RMI. Trivial to exploit, ubiquitous, and mass-exploited within hours of disclosure.