CVE-2026-28780·Apache vulnerability
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- Severity
- critical
- Software
- Apache
- Fixed in
- 2.4.67
- Published
- 2026-05-05
Affected versions
Until: 2.4.67
Fixed in: 2.4.67
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.67 or later to patch the heap buffer overflow in mod_proxy_ajp. This vulnerability allows a malicious AJP backend server to corrupt heap memory and potentially achieve remote code execution. Apply the update immediately, especially if your Apache instance is configured to proxy requests to untrusted or internet-facing AJP application servers.
sudo dnf update httpd httpd-coreDefensia detects this vulnerability
How to check if you are affected
- Check installed Apache version: apache2 -v | grep 'Server version' or httpd -v | grep 'Server version'
- Verify if mod_proxy_ajp is enabled: apache2ctl -M | grep proxy_ajp or httpd -M | grep proxy_ajp
- Search Apache error logs for AJP connection errors or segmentation faults: sudo grep -i 'ajp\|segfault\|buffer' /var/log/apache2/error.log
- Confirm the patch is applied by re-running apache2 -v and verifying the version is 2.4.67 or higher after update
FAQ
What is CVE-2026-28780?
CVE-2026-28780 is a critical heap buffer overflow in Apache's mod_proxy_ajp module that occurs when processing malformed AJP protocol messages from a backend server, allowing an attacker to write arbitrary data to heap memory.
Is CVE-2026-28780 being actively exploited?
No, this vulnerability is not currently listed as actively exploited by CISA, and no public exploits are available. However, the CVSS score of 9.8 indicates critical severity and warrants immediate patching.
What versions of Apache are affected by CVE-2026-28780?
All versions of Apache HTTP Server through 2.4.66 are vulnerable. Version 2.4.67 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-28780?
Run 'apache2 -v' or 'httpd -v' to check your version, and 'apache2ctl -M' or 'httpd -M' to confirm mod_proxy_ajp is loaded. If the version is below 2.4.67 and mod_proxy_ajp is active, your server is vulnerable.
Does Defensia detect CVE-2026-28780?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-28780 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-28780. Free for 1 server.
Get started free