Apache HTTP Server HTTP/2 double-free flaw
A double-free vulnerability in Apache HTTP Server's mod_http2 (CVE-2026-23918) can crash workers and, on some configs, enable remote code execution; PoC code exists.
CIS/MS-ISAC issued an advisory for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server's mod_http2 module affecting versions prior to 2.4.67. The flaw is triggered by a crafted HTTP/2 stream sequence that causes the same stream to be cleaned up twice, leading to memory corruption. At minimum this allows an unauthenticated attacker to crash worker processes, causing denial of service with minimal effort.
Of greater concern, in certain configurations — notably those using APR with mmap, which is common on Debian systems and official Docker images — the memory corruption may be leveraged for remote code execution. Proof-of-concept code exists for both the denial-of-service and code-execution scenarios, though the advisory does not indicate confirmed in-the-wild exploitation. Given Apache HTTP Server's ubiquity as internet-facing infrastructure, organizations running affected versions should prioritize patching to 2.4.67 or later.
MS-ISAC recommends standard vulnerability management practices: prompt patching, automated patch management, vulnerability scanning, network segmentation to isolate internet-facing services, least-privilege configurations, and anti-exploitation controls. No specific threat actor or malware campaign has been linked to this vulnerability at this time.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-apache-http-server-could-allow-for-remote-code-execution_2026-044
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free