ctipilot.ch

Apache HTTP Server 2.4.x — mod_proxy_ajp heap buffer overflow (RCE via AJP backend)

cve · CVE-2026-28780

Coverage timeline
2
first 2026-05-07 → last 2026-05-10
Briefs
2
2 distinct
Sources cited
22
19 hosts
Sections touched
2
updates, weekly_summary
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-10CTI Weekly Summary — 2026-W19 (May 04 – May 10, 2026)
    weekly_summaryConsolidated in weekly summary for week 2026-W19
  2. 2026-05-07CTI Daily Brief — 2026-05-07
    updatesFirst coverage (UPDATE to 2026-05-06 Apache item). mod_proxy_ajp heap buffer overflow via crafted AJP messages; fixed in Apache 2.4.67. Not retrieved in prior run.

Where this entity is cited

  • updates1
  • weekly_summary1

Source distribution

  • github.com4 (18%)
  • attack.mitre.org1 (5%)
  • badhost.org1 (5%)
  • blog.calif.io1 (5%)
  • cert.pl1 (5%)
  • cert.ssi.gouv.fr1 (5%)
  • cve.threatint.eu1 (5%)
  • httpd.apache.org1 (5%)
  • other11 (50%)

External references

NVD · cve.org · CISA KEV

All cited sources (22)

Items in briefs about Apache HTTP Server 2.4.x — mod_proxy_ajp heap buffer overflow (RCE via AJP backend)

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.