Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-44631: Apache2 package updated to fix security flaw

CVE-2026-44631 · published 3 days ago
Summary

The Apache2 web server package used on Debian 12 and several other distributions contained a security weakness that could be exploited by attackers. Updated versions of the package have been released that correct the problem. Install the latest Apache2 package from your distribution’s repository as soon as possible.

What to do
  • Update bellsoft apache2 to version 2.4.68-r0.
  • Update alpine apache2 to version 2.4.68-r0.
  • Update debian rootio-apache2 to version 2.4.67-1~deb12u3.root.io.11.
  • Update debian rootio-apache2 to version 2.4.67-1~deb13u3.root.io.3.
  • Update debian apache2 to version 2.4.67-1~deb13u3.root.io.3.
  • Update debian apache2 to version 2.4.68-1~deb12u1.
  • Update debian apache2 to version 2.4.68-1~deb13u1.
  • Update debian apache2 to version 2.4.68-1.
  • Update apache2 to version 2.4.68-r0.
  • Update apache2 to version 2.4.67-1~deb12u3.aikido.13.
  • Update rootio-apache2 to version 2.4.67-1~deb12u3.aikido.13.
  • Update apache2 to version 2.4.67-1~deb13u3.aikido.6.
  • Update rootio-apache2 to version 2.4.67-1~deb13u3.aikido.6.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian apache2 All versions
Debian:12 debian apache2 < 2.4.68-1~deb12u1
Fix: upgrade to 2.4.68-1~deb12u1
Debian:13 debian apache2 < 2.4.68-1~deb13u1
Fix: upgrade to 2.4.68-1~deb13u1
Debian:14 debian apache2 < 2.4.68-1
Fix: upgrade to 2.4.68-1
Alpaquita:stream bellsoft apache2 >= 2.4.56-r0, < 2.4.68-r0
Fix: upgrade to 2.4.68-r0
Alpine:v3.22 alpine apache2 < 2.4.68-r0
Fix: upgrade to 2.4.68-r0
Alpine:v3.23 alpine apache2 < 2.4.68-r0
Fix: upgrade to 2.4.68-r0
Alpine:v3.24 alpine apache2 < 2.4.68-r0
Fix: upgrade to 2.4.68-r0
Alpine:v3.21 alpine apache2 < 2.4.68-r0
Fix: upgrade to 2.4.68-r0
Root:Debian:12 debian rootio-apache2 < 2.4.67-1~deb12u3.root.io.11
Fix: upgrade to 2.4.67-1~deb12u3.root.io.11
Root:Debian:13 debian rootio-apache2 < 2.4.67-1~deb13u3.root.io.3
Fix: upgrade to 2.4.67-1~deb13u3.root.io.3
Root:Debian:13 debian apache2 < 2.4.67-1~deb13u3.root.io.3
Fix: upgrade to 2.4.67-1~deb13u3.root.io.3
Alpine:v3.21 – apache2 < 2.4.68-r0
Fix: upgrade to 2.4.68-r0
Root:Debian:12 – apache2 < 2.4.67-1~deb12u3.aikido.13
Fix: upgrade to 2.4.67-1~deb12u3.aikido.13
Root:Debian:12 – rootio-apache2 < 2.4.67-1~deb12u3.aikido.13
Fix: upgrade to 2.4.67-1~deb12u3.aikido.13
Root:Debian:13 – apache2 < 2.4.67-1~deb13u3.aikido.6
Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
Root:Debian:13 – rootio-apache2 < 2.4.67-1~deb13u3.aikido.6
Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
Original advisory text
CVE-2026-44631 in apache2 - Patched by Root
Root has patched CVE-2026-44631 in the apache2 package for Root:Debian:12. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-124Buffer Underwrite ('Buffer Underflow')
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen8 Jun 2026
Track software like this
Free during beta