Apache threat watch

Apache Software Foundation CVE coverage for web servers, middleware, libraries, and enterprise application components.

Watch items

Recent Apache watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows ยท sorted newest first

Operations view

lucy vulnerability (CVE-2026-61483)

HIGH
watchNVDCVE-2026-61483

UNSUPPORTED WHEN ASSIGNED Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Aug 5, 2026, 3:16 AMOfficial source

qpid broker-j vulnerability (CVE-2026-68073)

HIGH
watchNVDCVE-2026-68073

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

Aug 5, 2026, 2:16 AMOfficial source

nifi vulnerability (CVE-2026-68981)

HIGH
watchNVDCVE-2026-68981

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.

Aug 3, 2026, 3:17 PMOfficial source

nifi vulnerability (CVE-2026-68980)

LOW
watchNVDCVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

Aug 3, 2026, 3:17 PMOfficial source

nifi vulnerability (CVE-2026-68979)

MEDIUM
watchNVDCVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.

Aug 3, 2026, 3:17 PMOfficial source

tika vulnerability (CVE-2026-66756)

MEDIUM
watchNVDCVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

Jul 30, 2026, 3:18 PMOfficial source

tika vulnerability (CVE-2026-66755)

MEDIUM
watchNVDCVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.

Jul 30, 2026, 3:18 PMOfficial source

traffic server vulnerability (CVE-2026-58187)

MEDIUM
watchNVDCVE-2026-58187

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-58185)

HIGH
watchNVDCVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-58184)

HIGH
watchNVDCVE-2026-58184

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-58183)

HIGH
watchNVDCVE-2026-58183

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-58179)

CRITICAL
watchNVDCVE-2026-58179

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-58177)

HIGH
watchNVDCVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-58163)

HIGH
watchNVDCVE-2026-58163

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Jul 29, 2026, 5:16 AMOfficial source

traffic server vulnerability (CVE-2026-33267)

HIGH
watchNVDCVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Jul 29, 2026, 3:16 AMOfficial source

thrift vulnerability (CVE-2026-58662)

HIGH
watchNVDCVE-2026-58662

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Jul 27, 2026, 7:16 AMOfficial source

thrift vulnerability (CVE-2026-58389)

HIGH
watchNVDCVE-2026-58389

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Jul 27, 2026, 7:16 AMOfficial source

thrift vulnerability (CVE-2026-58023)

MEDIUM
watchNVDCVE-2026-58023

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Jul 27, 2026, 7:16 AMOfficial source

thrift vulnerability (CVE-2026-55971)

CRITICAL
watchNVDCVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Jul 27, 2026, 7:16 AMOfficial source

thrift vulnerability (CVE-2026-55969)

HIGH
watchNVDCVE-2026-55969

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Jul 27, 2026, 7:16 AMOfficial source

Vendor watch hub

What this page covers

The Apachewatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Apache activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

338

Active

40

Featured

130

Unique CVEs

20

Most recent entry

Aug 5, 2026, 3:16 AM

Feed refreshes daily ยท 5:15 a.m. Central

SourcesยทCISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published โ€” not our sync time.

Related vendors

Other cloud vendors in the radar

Vendor watch FAQ

Common questions

What is the Apache threat watch page?

It is the Apache-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Apache watch page?

Use it to confirm whether current Apache issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Apache security issues?

Yes. ITECS can help map Apache advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.