Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-42535: Apache2 could allow attackers to run code
CVE-2026-42535 · published 3 days ago
Summary
A security weakness in the Apache2 web server package for Debian‑based systems could let an attacker execute code on the server. The risk is that a compromised site could be used to steal data or disrupt services. Install the latest Apache2 updates from your distribution’s package manager as soon as possible to resolve the issue.
What to do
- Update bellsoft apache2 to version 2.4.68-r0.
- Update alpine apache2 to version 2.4.68-r0.
- Update debian apache2 to version 2.4.67-1~deb11u3.
- Update debian apache2 to version 2.4.68-1.
- Update debian rootio-apache2 to version 2.4.67-1~deb12u3.root.io.11.
- Update debian rootio-apache2 to version 2.4.67-1~deb13u3.root.io.3.
- Update debian apache2 to version 2.4.67-1~deb13u3.root.io.3.
- Update debian apache2 to version 2.4.68-1~deb12u1.
- Update debian apache2 to version 2.4.68-1~deb13u1.
- Update apache2 to version 2.4.68-r0.
- Update apache2 to version 2.4.67-1~deb13u3.aikido.6.
- Update rootio-apache2 to version 2.4.67-1~deb13u3.aikido.6.
- Update apache2 to version 2.4.67-1~deb12u3.aikido.13.
- Update rootio-apache2 to version 2.4.67-1~deb12u3.aikido.13.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | apache2 |
< 2.4.68-1 Fix: upgrade to 2.4.68-1
|
| Debian:11 | debian | apache2 |
< 2.4.67-1~deb11u3 Fix: upgrade to 2.4.67-1~deb11u3
|
| Debian:12 | debian | apache2 |
< 2.4.68-1~deb12u1 Fix: upgrade to 2.4.68-1~deb12u1
|
| Debian:13 | debian | apache2 |
< 2.4.68-1~deb13u1 Fix: upgrade to 2.4.68-1~deb13u1
|
| Alpaquita:stream | bellsoft | apache2 |
>= 2.4.56-r0, < 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Alpine:v3.22 | alpine | apache2 |
< 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Alpine:v3.23 | alpine | apache2 |
< 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Alpine:v3.24 | alpine | apache2 |
< 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Alpine:v3.21 | alpine | apache2 |
< 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Root:Debian:12 | debian | rootio-apache2 |
< 2.4.67-1~deb12u3.root.io.11 Fix: upgrade to 2.4.67-1~deb12u3.root.io.11
|
| Root:Debian:13 | debian | rootio-apache2 |
< 2.4.67-1~deb13u3.root.io.3 Fix: upgrade to 2.4.67-1~deb13u3.root.io.3
|
| Root:Debian:13 | debian | apache2 |
< 2.4.67-1~deb13u3.root.io.3 Fix: upgrade to 2.4.67-1~deb13u3.root.io.3
|
| Alpine:v3.21 | – | apache2 |
< 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Root:Debian:13 | – | apache2 |
< 2.4.67-1~deb13u3.aikido.6 Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
|
| Root:Debian:13 | – | rootio-apache2 |
< 2.4.67-1~deb13u3.aikido.6 Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
|
| Root:Debian:12 | – | apache2 |
< 2.4.67-1~deb12u3.aikido.13 Fix: upgrade to 2.4.67-1~deb12u3.aikido.13
|
| Root:Debian:12 | – | rootio-apache2 |
< 2.4.67-1~deb12u3.aikido.13 Fix: upgrade to 2.4.67-1~deb12u3.aikido.13
|
Original advisory text
CVE-2026-42535 in apache2 - Patched by Root
Root has patched CVE-2026-42535 in the apache2 package for Root:Debian:12. Multiple fixed versions available.
References
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://security-tracker.debian.org/tracker/CVE-2026-42535 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/08/8
- https://docs.bell-sw.com/security/cves/CVE-2026-42535 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-42535 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-668Exposure of Resource to Wrong Sphere
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen8 Jun 2026
Sources
CVE-2026-42535 · NVD
DEBIAN-CVE-2026-42535 · OSV
BELL-CVE-2026-42535 · OSV
ALPINE-CVE-2026-42535 · OSV
Track software like this
Free during beta