The Apache project released version 2.4.69 of its web server on October 1, 2026. It fixes 20 vulnerabilities that affect versions 2.4.0 through 2.4.68. Apache rates them low or moderate; Spain's INCIBE-CERT rates three as critical. If your website runs on Apache, check which version your server has.
What we know
- What shipped and when: Apache HTTP Server 2.4.69, on October 1, 2026, according to the project's vulnerabilities page and its home page.
- How many flaws: 20, each with its own CVE identifier. By Apache's own rating, 15 are low and 5 are moderate. None is listed as "important" or "critical". The tally is this article's count of the official list.
- Affected versions: up to 2.4.68. Most flaws go back to 2.4.0; one starts at 2.4.60 and another at 2.4.30.
- Where they are: in the server core and in specific modules. Among them: mod_http2 (HTTP/2), mod_rewrite (rewrite rules), mod_ssl, mod_dav and mod_dav_fs (WebDAV), mod_auth_digest, several proxy modules, mod_vhost_alias and mod_userdir. One of the moderate flaws affects Apache on Windows.
- How long they were known: Apache's security team received the reports between April 3 and August 14, 2026, according to the date on each entry.
- A second rating: INCIBE-CERT, Spain's national incident response team, published advisory INCIBE-2026-696 on October 2 with its top importance level, 5 (critical). It says 3 of the 20 are critical: the ones in mod_http2 (CVE-2026-57941), mod_rewrite (CVE-2026-56154) and mod_ssl (CVE-2026-59797). Apache rates the first as moderate and the other two as low.
- Exploitation: INCIBE-CERT's table shows "No" in the exploitation column for those three, as of its advisory date.
- The fix: upgrade to 2.4.69, according to both sources.
What changes and what doesn't
What changes: any Apache 2.4 older than 2.4.69 now has public flaws with a patch available. Since October 1 the list is there for everyone to read, including anyone scanning for servers that have not been updated.
Nothing changes if your site runs on a different server, such as LiteSpeed or nginx: this advisory is not about them. It is not a flaw in your content management system either. It is not in WordPress or Drupal, but in the program that delivers the pages.
Read the two ratings together. Apache, which wrote the fixes, says low and moderate. INCIBE-CERT says three are critical. Neither page explains the gap. INCIBE-CERT itself notes that some of the vulnerabilities only affect certain modules, configurations or version ranges. An old Apache is not necessarily exposed to all 20.
How to tell if it affects you
It affects you if your website or online store runs on Apache. Six steps:
- Find out which server your site uses. In cPanel, the "Server Information" page usually shows the Apache version. If your panel does not say, ask.
- On shared hosting, you cannot upgrade it yourself. Ask your provider: "Which Apache version does my account run, and when will you apply 2.4.69 or the patches for its CVEs?"
- On a VPS or your own server, the command "apachectl -v" prints the version (on Debian and Ubuntu, "apache2ctl -v"). Update through your system's package manager.
- Do not rely on the version number alone. Distributions such as Debian, Ubuntu or AlmaLinux usually patch the flaws without moving to 2.4.69. Look up the CVEs in your distribution's security advisories.
- Review the loaded modules with "apachectl -M". If you do not use WebDAV, mod_userdir or the FTP proxy, turn them off: fewer modules, fewer flaws that can reach you.
- Test the site after updating: home page, forms, admin area and the redirects in your .htaccess file.
Related: Microsoft: Flaws Are Weaponized in Under 24 Hours
Sources
- Apache HTTP Server Project, "Apache HTTP Server 2.4 vulnerabilities"
- Apache HTTP Server Project, home page listing version 2.4.69
- INCIBE-CERT, advisory INCIBE-2026-696, October 2, 2026 (in Spanish)
Updates: any change in severity by Apache or INCIBE-CERT, or confirmed exploitation, will be added here.