Apache
3,083 CVEs tracked since 1999. Since Sep 2021, 19 of them reached CISA KEV.
Apache CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 22 | 1 |
| 2021-10 | 15 | 2 |
| 2021-11 | 24 | 0 |
| 2021-12 | 14 | 2 |
| 2022-01 | 32 | 0 |
| 2022-02 | 14 | 1 |
| 2022-03 | 12 | 0 |
| 2022-04 | 11 | 1 |
| 2022-05 | 9 | 0 |
| 2022-06 | 18 | 0 |
| 2022-07 | 13 | 1 |
| 2022-08 | 26 | 0 |
| 2022-09 | 26 | 0 |
| 2022-10 | 17 | 0 |
| 2022-11 | 27 | 0 |
| 2022-12 | 18 | 0 |
| 2023-01 | 25 | 0 |
| 2023-02 | 16 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 21 | 1 |
| 2023-05 | 31 | 1 |
| 2023-06 | 16 | 0 |
| 2023-07 | 29 | 0 |
| 2023-08 | 16 | 0 |
| 2023-09 | 17 | 0 |
| 2023-10 | 25 | 2 |
| 2023-11 | 26 | 0 |
| 2023-12 | 28 | 0 |
| 2024-01 | 15 | 0 |
| 2024-02 | 41 | 0 |
| 2024-03 | 28 | 0 |
| 2024-04 | 27 | 1 |
| 2024-05 | 8 | 1 |
| 2024-06 | 10 | 0 |
| 2024-07 | 46 | 1 |
| 2024-08 | 20 | 1 |
| 2024-09 | 14 | 1 |
| 2024-10 | 15 | 0 |
| 2024-11 | 26 | 0 |
| 2024-12 | 17 | 0 |
| 2025-01 | 16 | 0 |
| 2025-02 | 13 | 0 |
| 2025-03 | 23 | 1 |
| 2025-04 | 19 | 0 |
| 2025-05 | 15 | 0 |
| 2025-06 | 21 | 0 |
| 2025-07 | 24 | 0 |
| 2025-08 | 20 | 0 |
| 2025-09 | 10 | 0 |
| 2025-10 | 20 | 0 |
| 2025-11 | 19 | 0 |
| 2025-12 | 20 | 0 |
| 2026-01 | 22 | 0 |
| 2026-02 | 20 | 0 |
| 2026-03 | 20 | 0 |
| 2026-04 | 84 | 1 |
| 2026-05 | 80 | 0 |
| 2026-06 | 110 | 0 |
| 2026-07 | 116 | 0 |
| 2026-08 | 163 | 0 |
| 2026-09 | 38 | 0 |
Products
The products that kept showing up in Apache's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache.
- CVE-2026-86473Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry9.1
- CVE-2026-75158Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter4.3
- CVE-2026-82355Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation4.2
- CVE-2026-91867Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely4.3
- CVE-2026-91866Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service7.5
- CVE-2026-91865Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service7.5
- CVE-2026-91864Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion7.5
- CVE-2026-91863Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service7.5
- CVE-2026-70469Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests7.5
- CVE-2026-81866Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration4.3
- CVE-2026-82561Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods6.5
- CVE-2026-86089Apache NiFi: Missing Process Group Authorization for Connector Migration7.1
- CVE-2026-87976Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles8.1
- CVE-2026-84501Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider5.3
- CVE-2026-84439Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources5.3
The record
- Peak rank
- #3 in Jan 2012
- Busiest month shown
- Aug 2026, 163 CVEs
- Months with a KEV entry
- 16 since Sep 2021
- Monthly snapshots
- 261 since 1999