Synced 03 Aug 2026 05:54 UTC Account
← All products

Apache HTTP Server

Apache · Web / Runtime
↻ RSS feed
Monitors Apache HTTP Server and tailors your dashboard to that exact version.
2.4.68 · latest cycle100/100 Healthy

Summary iPlain-English security verdict for Apache HTTP Server, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.

Apache HTTP Server currently scores 100/100 — healthy. 1 actively-exploited vulnerability (CISA KEV) affects older releases (e.g. CVE-2021-40438) — staying on the latest supported version keeps you clear of it. The latest supported release is 2.4.68. It's on the latest patch with no significant known issues — keep it current.

Disclosure trend iNew CVEs published for Apache HTTP Server each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.

'19
'20
'21
'22
'23
'24
'25
'26

1 of its known vulnerability is linked to ransomware campaigns (CISA KEV).

Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.

Most urgent first — actively exploited, then likeliest to be exploited.

CVE-2021-40438 CRITICAL exploited ransomware Server-side request forgery (SSRF) EPSS 100% → see advisory CVE-2026-23918 HIGH Double free EPSS 46% → see advisory CVE-2026-28780 CRITICAL CWE-122 EPSS 1% → fixed in 2.4.67 CVE-2026-29167 CRITICAL Use-after-free EPSS 1% → fixed in 2.4.68 CVE-2026-42535 CRITICAL CWE-668 EPSS 1% → fixed in 2.4.68 CVE-2026-44631 CRITICAL CWE-124 EPSS 0% → fixed in 2.4.68

See all 18 known Apache HTTP Server CVEs & security history →

Get alerted about Apache HTTP Server

Be emailed the moment Apache HTTP Server gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.

We email only on real events for Apache HTTP Server — no marketing, no sharing, and we never know what you run. Track your whole stack →

Monitor up to 200 products — freeHit ☆ Monitor on anything you run, then sign in (no password) to sync your stack across devices and unlock smart insights, risk history & CSV/JSON exports. Sign in free →

Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.

How long each Apache HTTP Server release line is supported — and when it sunsets. Select a line for its full report.

Jul11'17 Apache HTTP Server 2.2ended 2017-07-11
Jul10'13 Apache HTTP Server 2.0ended 2013-07-10
Feb3'10 Apache HTTP Server 1.3ended 2010-02-03

Full Apache HTTP Server end-of-life dates & support timeline →

2.4 latest 2.4.68 Supported 2.4.68 → 2.2 latest 2.2.34 End of life ended 2017-07-112.2.34 → 2.0 latest 2.0.65 End of life ended 2013-07-102.0.65 → 1.3 latest 1.3.42 End of life ended 2010-02-031.3.42 → See all upcoming end-of-life dates →

Frequently asked

Is Apache HTTP Server safe and patched?

Apache HTTP Server currently scores 100/100 — healthy. 1 actively-exploited vulnerability (CISA KEV) affects older releases (e.g. CVE-2021-40438) — staying on the latest supported version keeps you clear of it. The latest supported release is 2.4.68. It's on the latest patch with no significant known issues — keep it current.

What should I do about Apache HTTP Server now?

Upgrade Apache HTTP Server to the latest supported release (2.4.68) or later, which clears the actively-exploited issues affecting older versions, then confirm against Apache's official advisory.

When does Apache HTTP Server reach end-of-life?

The latest supported Apache HTTP Server release is 2.4.68. After end-of-life a release no longer receives security patches.

Which versions of Apache HTTP Server are still receiving security updates?

Supported Apache HTTP Server release lines (latest 2.4.68): 2.4. End-of-life releases no longer receive security patches.

Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Apache's official advisory before you patch or upgrade — Apache HTTP Server official site ↗