chiprook
← Security
SecurityOctober 6, 2026, 06:20

CVE-2026-102795: access control flaw in Apache Traffic Server

Apache Traffic Server has an improper access control flaw tied to SNI-to-Host header matching policy. Versions 9.0.0–9.2.14 and 10.0.0–10.1.3 are affected; fixes ship in 9.2.15 and 10.1.4. No exploitation in the wild has been reported, while ZoomEye counted 311,469 exposed instances.

CVE-2026-102795: access control flaw in Apache Traffic Server
#Apache
Read next
Security

Genea launches MCP server to bring AI agents to access control

Security

CVE-2026-76441: Access Control Bypass in Cisco Secure Email Gateway

Security

NIO ES8 in Norwegian Mine: 90% of Traffic Went to Chinese Servers

Security

Apache Tomcat patch matrix for CVE-2026-86350