Memory Allocation Vulnerability in Apache HTTP Server by Apache
CVE-2026-49975

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 June 2026

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 3,610πŸ’° RansomwareπŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-49975?

false

Affected Version(s)

Apache HTTP Server 2.4.17 <= 2.4.67

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

ThreatsDay Bulletin covers AI abuse, poisoned packages, phishing, macOS attacks, SD-WAN flaws, scams, and supply-chain threats this week.

2 weeks ago

IT, Telcos, Healthcare at Risk of HTTP/2 DDoS Attacks

The denial-of-service (DoS) exploit takes advantage of two features in HTTP/2 that were designed to save Internet bandwith.

2 weeks ago

IT Security News Hourly Summary 2026-06-04 21h : 6 posts - IT Security News

6 posts were published in the last hour 18:34 : Gartner SRM 2026 Signals a Cybersecurity Shift From Prevention to Resilience 18:34 : Imperva Customers Protected Against CVE-2026-49975 (HTTP/2 Bomb) DoS 18:34 : Cybercriminals Shift From Fake Login Pages to…Read more β†’

4 weeks ago

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ’°

    Used in Ransomware

  • πŸ“ˆ

    Vulnerability started trending

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • πŸ“°

    First article discovered by It Security News

  • Vulnerability Reserved

Credit

Quang Luong of Calif.IO in collaboration with OpenAI Codex
.