Apache 2.4.x < 2.4.69 Multiple Vulnerabilities

critical Nessus Plugin ID 362655

Synopsis

The remote web server is affected by multiple vulnerabilities.

Description

The version of Apache httpd installed on the remote host is prior to 2.4.69. It is, therefore, affected by multiple vulnerabilities as referenced in the 2.4.69 advisory.

- Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file- related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. (CVE-2026-59797)

- Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68. (CVE-2026-42356)

- A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue (CVE-2026-42528)

- NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. (CVE-2026-46729)

- Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
(CVE-2026-47360)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache version 2.4.69 or later.

Plugin Details

Severity: Critical

ID: 362655

File Name: apache_2_4_69.nasl

Version: 1.1

Type: Combined

Agent: windows, macosx, unix

Family: Web Servers

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.17

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-59797

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:http_server, cpe:/a:apache:httpd

Required KB Items: installed_sw/Apache

Exploit Ease: No known exploits are available

Patch Publication Date: 10/1/2026

Vulnerability Publication Date: 4/3/2026

Reference Information

CVE: CVE-2026-42356, CVE-2026-42528, CVE-2026-46729, CVE-2026-47360, CVE-2026-48005, CVE-2026-56153, CVE-2026-56154, CVE-2026-56449, CVE-2026-57941, CVE-2026-58415, CVE-2026-59685, CVE-2026-59797, CVE-2026-63045, CVE-2026-63292, CVE-2026-63686, CVE-2026-63718, CVE-2026-73636, CVE-2026-73637, CVE-2026-79768, CVE-2026-93546