Overview
What is CVE-2026-23918?
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Vulnerability intelligence
CVE-2026-23918 and is rated High severity with a CVSS score of 8.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Public exploit: Cataloged public exploit.
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.