CVE-2026-89282: Apache HTTP Server Project Apache Lounge Windows
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.
Affected products
- Apache HTTP Server Project Apache Lounge Windows
Published 2026-09-22. Last modified 2026-09-23.