Apache HTTP Server ↗
Summary iPlain-English security verdict for Apache HTTP Server, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.
Apache HTTP Server currently scores 100/100 — healthy. 1 actively-exploited vulnerability (CISA KEV) affects older releases (e.g. CVE-2021-40438) — staying on the latest supported version keeps you clear of it. The latest supported release is 2.4.68. It's on the latest patch with no significant known issues — keep it current.
Disclosure trend iNew CVEs published for Apache HTTP Server each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.
1 of its known vulnerability is linked to ransomware campaigns (CISA KEV).
Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.
Most urgent first — actively exploited, then likeliest to be exploited.
CVE-2021-40438 CRITICAL exploited ransomware Server-side request forgery (SSRF) EPSS 100% → see advisory CVE-2026-23918 HIGH Double free EPSS 46% → see advisory CVE-2026-28780 CRITICAL CWE-122 EPSS 1% → fixed in 2.4.67 CVE-2026-29167 CRITICAL Use-after-free EPSS 1% → fixed in 2.4.68 CVE-2026-42535 CRITICAL CWE-668 EPSS 1% → fixed in 2.4.68 CVE-2026-44631 CRITICAL CWE-124 EPSS 0% → fixed in 2.4.68See all 18 known Apache HTTP Server CVEs & security history →
Get alerted about Apache HTTP Server
Be emailed the moment Apache HTTP Server gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.
We email only on real events for Apache HTTP Server — no marketing, no sharing, and we never know what you run. Track your whole stack →
Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.
How long each Apache HTTP Server release line is supported — and when it sunsets. Select a line for its full report.
Full Apache HTTP Server end-of-life dates & support timeline →
2.4 latest 2.4.68 Supported 2.4.68 → 2.2 latest 2.2.34 End of life ended 2017-07-112.2.34 → 2.0 latest 2.0.65 End of life ended 2013-07-102.0.65 → 1.3 latest 1.3.42 End of life ended 2010-02-031.3.42 → See all upcoming end-of-life dates →Frequently asked
Is Apache HTTP Server safe and patched?
Apache HTTP Server currently scores 100/100 — healthy. 1 actively-exploited vulnerability (CISA KEV) affects older releases (e.g. CVE-2021-40438) — staying on the latest supported version keeps you clear of it. The latest supported release is 2.4.68. It's on the latest patch with no significant known issues — keep it current.
What should I do about Apache HTTP Server now?
Upgrade Apache HTTP Server to the latest supported release (2.4.68) or later, which clears the actively-exploited issues affecting older versions, then confirm against Apache's official advisory.
When does Apache HTTP Server reach end-of-life?
The latest supported Apache HTTP Server release is 2.4.68. After end-of-life a release no longer receives security patches.
Which versions of Apache HTTP Server are still receiving security updates?
Supported Apache HTTP Server release lines (latest 2.4.68): 2.4. End-of-life releases no longer receive security patches.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Apache's official advisory before you patch or upgrade — Apache HTTP Server official site ↗