chiprook
← Security
SecurityOctober 10, 2026, 23:40

Apache httpd 2.4.69 fixes 20 flaws, including CVE-2026-63292

Apache HTTP Server 2.4.69 was released on 1 October 2026, fixing twenty security issues in the 2.4 branch. The key one, CVE-2026-63292, is a stack-based buffer overflow in mod_vhost_alias affecting every release from 2.4.0 through 2.4.68; the patch bounds the buffer when expanding the Host header.

Apache httpd 2.4.69 fixes 20 flaws, including CVE-2026-63292
#Apache
Read next
Security

Apache Tomcat 11.0.26 fixes HTTP/2 header mix-up regression CVE-2026-86350

Security

Apache fixes two DoS flaws in NiFi and MyFaces

Security

Adobe fixes 18 critical Campaign Classic flaws, including a 10.0 CVE

Security

Exim 4.100.1 fixes four flaws, including Proxy Protocol and SMTP smuggling