CVE-2026-42535: Apache HTTP Server

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Affected products

  • Apache HTTP Server: before 2.4.68 (fixed in 2.4.68)

Published 2026-06-08. Last modified 2026-07-23.