Apache known exploited vulnerabilities
CISA lists 40 Apache CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-08-04), and 8 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-44228 (Log4j2): EPSS 100.0%, added 2021-12-10
- CVE-2021-40438 (Apache): EPSS 100.0%, added 2021-12-01
- CVE-2017-5638 (Struts): EPSS 100.0%, added 2021-11-03
- CVE-2013-2251 (Struts): EPSS 100.0%, added 2022-03-25
- CVE-2021-41773 (HTTP Server): EPSS 100.0%, added 2021-11-03
Most affected Apache products
Tomcat (6), Struts (5), HTTP Server (4), ActiveMQ (3), OFBiz (3), Log4j2 (2), Struts 1 (2), Solr (2), HugeGraph-Server (1), Flink (1), Superset (1), RocketMQ (1).
All Apache CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-34486 | Tomcat | Tomcat Missing Encryption of Sensitive Data | 2026-08-04 | 2026-08-07 | 6.6% | – |
| CVE-2026-34197 | ActiveMQ | ActiveMQ Improper Input Validation | 2026-04-16 | 2026-04-30 | 15.5% | – |
| CVE-2024-38475 | HTTP Server | HTTP Server Improper Escaping of Output | 2025-05-01 | 2025-05-22 | 100.0% | – |
| CVE-2025-24813 | Tomcat | Tomcat Path Equivalence | 2025-04-01 | 2025-04-22 | 99.9% | – |
| CVE-2024-45195 | OFBiz | OFBiz Forced Browsing | 2025-02-04 | 2025-02-25 | 100.0% | – |
| CVE-2024-27348 | HugeGraph-Server | HugeGraph-Server Improper Access Control | 2024-09-18 | 2024-10-09 | 99.2% | – |
| CVE-2024-38856 | OFBiz | OFBiz Incorrect Authorization | 2024-08-27 | 2024-09-17 | 99.4% | – |
| CVE-2024-32113 | OFBiz | OFBiz Path Traversal | 2024-08-07 | 2024-08-28 | 99.9% | – |
| CVE-2020-17519 | Flink | Flink Improper Access Control | 2024-05-23 | 2024-06-13 | 97.8% | – |
| CVE-2023-27524 | Superset | Superset Insecure Default Initialization of Resource | 2024-01-08 | 2024-01-29 | 97.4% | – |
| CVE-2023-46604 | ActiveMQ | ActiveMQ Deserialization of Untrusted Data | 2023-11-02 | 2023-11-23 | 99.9% | Yes |
| CVE-2023-33246 | RocketMQ | RocketMQ Command Execution | 2023-09-06 | 2023-09-27 | 96.6% | – |
| CVE-2016-8735 | Tomcat | Tomcat Remote Code Execution | 2023-05-12 | 2023-06-02 | 90.3% | – |
| CVE-2021-45046 | Log4j2 | Log4j2 Deserialization of Untrusted Data | 2023-05-01 | 2023-05-22 | 100.0% | Yes |
| CVE-2022-33891 | Spark | Spark Command Injection | 2023-03-07 | 2023-03-28 | 93.1% | – |
| CVE-2022-24706 | CouchDB | CouchDB Insecure Default Initialization of Resource | 2022-08-25 | 2022-09-15 | 92.5% | – |
| CVE-2022-24112 | APISIX | APISIX Authentication Bypass | 2022-08-25 | 2022-09-15 | 96.1% | – |
| CVE-2020-1956 | Kylin | Kylin OS Command Injection | 2022-03-25 | 2022-04-15 | 97.3% | – |
| CVE-2017-12617 | Tomcat | Tomcat Remote Code Execution | 2022-03-25 | 2022-04-15 | 100.0% | – |
| CVE-2017-12615 | Tomcat | Tomcat on Windows Remote Code Execution | 2022-03-25 | 2022-04-15 | 99.6% | Yes |
| CVE-2013-2251 | Struts | Struts Improper Input Validation | 2022-03-25 | 2022-04-15 | 100.0% | – |
| CVE-2020-1938 | Tomcat | Tomcat Improper Privilege Management | 2022-03-03 | 2022-03-17 | 99.3% | – |
| CVE-2017-9791 | Struts 1 | Struts 1 Improper Input Validation | 2022-02-10 | 2022-08-10 | 98.9% | – |
| CVE-2016-3088 | ActiveMQ | ActiveMQ Improper Input Validation | 2022-02-10 | 2022-08-10 | 98.5% | – |
| CVE-2012-0391 | Struts 2 | Struts 2 Improper Input Validation | 2022-01-21 | 2022-07-21 | 75.6% | – |
| CVE-2006-1547 | Struts 1 | Struts 1 ActionForm Denial-of-Service | 2022-01-21 | 2022-07-21 | 54.6% | – |
| CVE-2020-13927 | Airflow's Experimental API | Airflow's Experimental API Authentication Bypass | 2022-01-18 | 2022-07-18 | 99.8% | – |
| CVE-2020-11978 | Airflow | Airflow Command Injection | 2022-01-18 | 2022-07-18 | 99.2% | – |
| CVE-2021-44228 | Log4j2 | Log4j2 Remote Code Execution | 2021-12-10 | 2021-12-24 | 100.0% | Yes |
| CVE-2019-0193 | Solr | Solr DataImportHandler Code Injection | 2021-12-10 | 2022-06-10 | 83.5% | – |
| CVE-2021-40438 | Apache | HTTP Server-Side Request Forgery (SSRF) | 2021-12-01 | 2021-12-15 | 100.0% | Yes |
| CVE-2021-42013 | HTTP Server | HTTP Server Path Traversal | 2021-11-03 | 2021-11-17 | 100.0% | Yes |
| CVE-2021-41773 | HTTP Server | HTTP Server Path Traversal | 2021-11-03 | 2021-11-17 | 100.0% | Yes |
| CVE-2020-17530 | Struts | Struts Remote Code Execution | 2021-11-03 | 2022-05-03 | 95.9% | – |
| CVE-2019-17558 | Solr | Solr VelocityResponseWriter Plug-In Remote Code Execution | 2021-11-03 | 2022-05-03 | 98.6% | – |
| CVE-2019-0211 | HTTP Server | HTTP Server Privilege Escalation | 2021-11-03 | 2022-05-03 | 65.0% | – |
| CVE-2018-11776 | Struts | Struts Remote Code Execution | 2021-11-03 | 2022-05-03 | 100.0% | – |
| CVE-2017-9805 | Struts | Struts Deserialization of Untrusted Data | 2021-11-03 | 2022-05-03 | 99.4% | – |
| CVE-2017-5638 | Struts | Struts Remote Code Execution | 2021-11-03 | 2022-05-03 | 100.0% | Yes |
| CVE-2016-4437 | Shiro | Shiro Code Execution | 2021-11-03 | 2022-05-03 | 93.0% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors