CyberMax
Home › Exploited CVEs

Apache known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 40 Apache CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-08-04), and 8 are known to be used in ransomware campaigns.

Apache CVEs added to CISA KEV per year
2021: 122021122022: 132022132023: 5202352024: 5202452025: 3202532026: 220262

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Apache products

Tomcat (6), Struts (5), HTTP Server (4), ActiveMQ (3), OFBiz (3), Log4j2 (2), Struts 1 (2), Solr (2), HugeGraph-Server (1), Flink (1), Superset (1), RocketMQ (1).

All Apache CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-34486TomcatTomcat Missing Encryption of Sensitive Data2026-08-042026-08-076.6%–
CVE-2026-34197ActiveMQActiveMQ Improper Input Validation2026-04-162026-04-3015.5%–
CVE-2024-38475HTTP ServerHTTP Server Improper Escaping of Output2025-05-012025-05-22100.0%–
CVE-2025-24813TomcatTomcat Path Equivalence2025-04-012025-04-2299.9%–
CVE-2024-45195OFBizOFBiz Forced Browsing2025-02-042025-02-25100.0%–
CVE-2024-27348HugeGraph-ServerHugeGraph-Server Improper Access Control2024-09-182024-10-0999.2%–
CVE-2024-38856OFBizOFBiz Incorrect Authorization2024-08-272024-09-1799.4%–
CVE-2024-32113OFBizOFBiz Path Traversal2024-08-072024-08-2899.9%–
CVE-2020-17519FlinkFlink Improper Access Control2024-05-232024-06-1397.8%–
CVE-2023-27524SupersetSuperset Insecure Default Initialization of Resource2024-01-082024-01-2997.4%–
CVE-2023-46604ActiveMQActiveMQ Deserialization of Untrusted Data2023-11-022023-11-2399.9%Yes
CVE-2023-33246RocketMQRocketMQ Command Execution2023-09-062023-09-2796.6%–
CVE-2016-8735TomcatTomcat Remote Code Execution2023-05-122023-06-0290.3%–
CVE-2021-45046Log4j2Log4j2 Deserialization of Untrusted Data2023-05-012023-05-22100.0%Yes
CVE-2022-33891SparkSpark Command Injection2023-03-072023-03-2893.1%–
CVE-2022-24706CouchDBCouchDB Insecure Default Initialization of Resource2022-08-252022-09-1592.5%–
CVE-2022-24112APISIXAPISIX Authentication Bypass2022-08-252022-09-1596.1%–
CVE-2020-1956KylinKylin OS Command Injection2022-03-252022-04-1597.3%–
CVE-2017-12617TomcatTomcat Remote Code Execution2022-03-252022-04-15100.0%–
CVE-2017-12615TomcatTomcat on Windows Remote Code Execution2022-03-252022-04-1599.6%Yes
CVE-2013-2251StrutsStruts Improper Input Validation2022-03-252022-04-15100.0%–
CVE-2020-1938TomcatTomcat Improper Privilege Management2022-03-032022-03-1799.3%–
CVE-2017-9791Struts 1Struts 1 Improper Input Validation2022-02-102022-08-1098.9%–
CVE-2016-3088ActiveMQActiveMQ Improper Input Validation2022-02-102022-08-1098.5%–
CVE-2012-0391Struts 2Struts 2 Improper Input Validation2022-01-212022-07-2175.6%–
CVE-2006-1547Struts 1Struts 1 ActionForm Denial-of-Service2022-01-212022-07-2154.6%–
CVE-2020-13927Airflow's Experimental APIAirflow's Experimental API Authentication Bypass2022-01-182022-07-1899.8%–
CVE-2020-11978AirflowAirflow Command Injection2022-01-182022-07-1899.2%–
CVE-2021-44228Log4j2Log4j2 Remote Code Execution2021-12-102021-12-24100.0%Yes
CVE-2019-0193SolrSolr DataImportHandler Code Injection2021-12-102022-06-1083.5%–
CVE-2021-40438ApacheHTTP Server-Side Request Forgery (SSRF)2021-12-012021-12-15100.0%Yes
CVE-2021-42013HTTP ServerHTTP Server Path Traversal2021-11-032021-11-17100.0%Yes
CVE-2021-41773HTTP ServerHTTP Server Path Traversal2021-11-032021-11-17100.0%Yes
CVE-2020-17530StrutsStruts Remote Code Execution2021-11-032022-05-0395.9%–
CVE-2019-17558SolrSolr VelocityResponseWriter Plug-In Remote Code Execution2021-11-032022-05-0398.6%–
CVE-2019-0211HTTP ServerHTTP Server Privilege Escalation2021-11-032022-05-0365.0%–
CVE-2018-11776StrutsStruts Remote Code Execution2021-11-032022-05-03100.0%–
CVE-2017-9805StrutsStruts Deserialization of Untrusted Data2021-11-032022-05-0399.4%–
CVE-2017-5638StrutsStruts Remote Code Execution2021-11-032022-05-03100.0%Yes
CVE-2016-4437ShiroShiro Code Execution2021-11-032022-05-0393.0%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors