Microsoft Security Response Center guidance
Vendor revision: Oct 7, 2026Release Notes
Vulnerability intelligence
CVE-2026-59685 and is rated High severity with a CVSS score of 7.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Source: NVD