Apache fixes serious HTTP/2 vulnerability in its web server

Apache has released version 2.4.67 of Apache HTTP Server to fix CVE-2026-23918, a high-severity flaw in HTTP/2 handling. It carries a CVSS score of 8.8, affects version 2.4.66, and can be used for denial-of-service attacks and, under certain conditions, code execution. Researchers say the vulnerability can reliably crash affected servers, while successful code execution would likely require additional insight into memory layout or chaining with other flaws. There are no confirmed reports of exploitation, but researchers expect attempts to appear because triggering disruption is easy.

What this means for your organisation

HTTP/2 is usually enabled by default on servers exposing websites and APIs to the internet. That makes the bar low for anyone who wants to disrupt operations, and a simple, reliable crash is something attackers adopt quickly. For organisations with customer-facing services this is first and foremost an availability risk, and availability is one of the things NIS2 expects management to have a view on.

Berigo recommends

  • Update to Apache HTTP Server 2.4.67, starting with internet-facing servers.
  • Temporarily disable HTTP/2 where patching cannot be done quickly and the performance cost is acceptable.
  • Confirm that monitoring actually alerts when a web server process crashes and restarts repeatedly.
  • Consider whether critical services have enough redundancy to survive a single server going down.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch