CVE-2026-89281: Apache HTTP Server Project Apache Lounge Windows

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

Affected products

Published 2026-09-22. Last modified 2026-09-23.