Skip to content

Data collected

CVEs Live

Apache vulnerabilities exploited in the wild

The Apache CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

40
flaws with confirmed attacks
8
used by ransomware
2.3%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-34486Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · Tomcat

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    6.56%94th pct

    KEV dates

    added due
  2. CVE-2026-34197Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · ActiveMQ

    Apache ActiveMQ Improper Input Validation Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    15.5%97th pct

    KEV dates

    added due
  3. CVE-2024-38475Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · HTTP Server

    Apache HTTP Server Improper Escaping of Output Vulnerability

    Severity

    9.1CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.957%100th pct

    KEV dates

    added due
  4. CVE-2025-24813Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · Tomcat

    Apache Tomcat Path Equivalence Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.9%100th pct

    KEV dates

    added due
  5. CVE-2024-45195Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · OFBiz

    Apache OFBiz Forced Browsing Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.983%100th pct

    KEV dates

    added due
  6. CVE-2024-27348Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · HugeGraph-Server

    Apache HugeGraph-Server Improper Access Control Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.2%99.9th pct

    KEV dates

    added due
  7. CVE-2024-38856Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · OFBiz

    Apache OFBiz Incorrect Authorization Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.4%99.9th pct

    KEV dates

    added due
  8. CVE-2024-32113Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · OFBiz

    Apache OFBiz Path Traversal Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.9%100th pct

    KEV dates

    added due
  9. CVE-2020-17519Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · Flink

    Apache Flink Improper Access Control Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    97.8%99.9th pct

    KEV dates

    added due
  10. CVE-2023-27524Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · Superset

    Apache Superset Insecure Default Initialization of Resource Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    97.4%99.9th pct

    KEV dates

    added due
  11. CVE-2023-46604Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Apache · ActiveMQ

    Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.9%100th pct

    KEV dates

    added due
  12. CVE-2023-33246Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apache · RocketMQ

    Apache RocketMQ Command Execution Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    96.6%99.9th pct

    KEV dates

    added due

Apache products in the catalog

Among the most recent entries, the products that appear most often are:

  • OFBiz3 entries
  • Tomcat2 entries
  • ActiveMQ2 entries
  • HTTP Server1 entry
  • HugeGraph-Server1 entry
  • Flink1 entry
  • Superset1 entry
  • RocketMQ1 entry

Product names are the ones CISA uses in the catalog. To check a specific Apache CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: Apache Software Foundation security.

Other vendors

Questions

How many Apache vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 40 Apache vulnerabilities as of 3 Oct 2026. CISA marks 8 of them as known to be used in ransomware campaigns.

What is the most recent Apache entry in KEV?

CVE-2026-34486 (Apache Tomcat Missing Encryption of Sensitive Data Vulnerability), added on 4 Aug 2026 with a due date of 7 Aug 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Apache CVE?

No. It lists only the Apache CVEs that CISA has confirmed as exploited. Apache publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Apache vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections