CVE Tools

Apache

3,083 CVEs tracked since 1999. Since Sep 2021, 19 of them reached CISA KEV.

Apache CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09221
2021-10152
2021-11240
2021-12142
2022-01320
2022-02141
2022-03120
2022-04111
2022-0590
2022-06180
2022-07131
2022-08260
2022-09260
2022-10170
2022-11270
2022-12180
2023-01250
2023-02160
2023-03null or fewer
2023-04211
2023-05311
2023-06160
2023-07290
2023-08160
2023-09170
2023-10252
2023-11260
2023-12280
2024-01150
2024-02410
2024-03280
2024-04271
2024-0581
2024-06100
2024-07461
2024-08201
2024-09141
2024-10150
2024-11260
2024-12170
2025-01160
2025-02130
2025-03231
2025-04190
2025-05150
2025-06210
2025-07240
2025-08200
2025-09100
2025-10200
2025-11190
2025-12200
2026-01220
2026-02200
2026-03200
2026-04841
2026-05800
2026-061100
2026-071160
2026-081630
2026-09380

Products

The products that kept showing up in Apache's monthly top three, with their CVEs summed over those months.

  1. Airflow9817 months
  2. HTTP Server7713 months
  3. Superset5113 months
  4. Camel453 months
  5. Cloudstack427 months
  6. Traffic Server429 months
  7. Tomcat3610 months
  8. Ofbiz274 months
  9. Inlong256 months
  10. Zeppelin184 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Apache.

  1. CVE-2026-86473Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry9.1
  2. CVE-2026-75158Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter4.3
  3. CVE-2026-82355Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation4.2
  4. CVE-2026-91867Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely4.3
  5. CVE-2026-91866Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service7.5
  6. CVE-2026-91865Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service7.5
  7. CVE-2026-91864Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion7.5
  8. CVE-2026-91863Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service7.5
  9. CVE-2026-70469Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests7.5
  10. CVE-2026-81866Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration4.3
  11. CVE-2026-82561Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods6.5
  12. CVE-2026-86089Apache NiFi: Missing Process Group Authorization for Connector Migration7.1
  13. CVE-2026-87976Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles8.1
  14. CVE-2026-84501Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider5.3
  15. CVE-2026-84439Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources5.3

The record

Peak rank
#3 in Jan 2012
Busiest month shown
Aug 2026, 163 CVEs
Months with a KEV entry
16 since Sep 2021
Monthly snapshots
261 since 1999
Apache's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store