Security NEXT•October 2, 2026•🇯🇵Translated from Japanese

Apache HTTP Server 2.4.69 Patches 20 Vulnerabilities Including CVSS 9.8 Issues

The Apache HTTP Server development team has released version 2.4.69 on October 1, 2026, resolving 20 security vulnerabilities across the widely used web server software.

Although the Apache Security Team rated the overall impact as relatively low, multiple issues carry CVSS base scores of 9.8. The update contains no vulnerabilities classified as Critical or Important under the four-tier severity system used by developers.

Five vulnerabilities were rated Moderate, including conditions that could allow code execution or denial of service under specific configurations. The remaining 15 issues were assessed as Low severity.

Key vulnerabilities addressed

  • CVE-2026-63292: A stack-based buffer overflow in the mod_vhost_alias module that may lead to denial of service or arbitrary code execution when a virtual host receives a Host header exceeding 8192 bytes.
  • CVE-2026-57941: A use-after-free vulnerability in the mod_http2 module.
  • CVE-2026-59685: An out-of-bounds write during path processing on Windows systems, affecting mod_dav and mod_dav_fs.

Administrators are advised to upgrade to Apache HTTP Server 2.4.69 to mitigate these risks.

Related articles

Hispasec•Vulnerabilities & Exploits

BrokenPipe PoC Exploits Steam Client Service for Silent SYSTEM Privilege Escalation on Windows

A new proof-of-concept named BrokenPipe demonstrates how a standard Windows user can escalate privileges to NT AUTHORITY\SYSTEM through the Steam Client Service without requiring administrator credentials or triggering a UAC prompt. The vulnerability stems from insufficient signature validation in VDF installation scripts processed by steamservice.exe, allowing an attacker to control the execution path of a malicious script. The issue affects Steam version 10.96.30.42 on both Windows 10 and Windows 11, though no public CVE has been assigned yet. Valve was notified of the flaw in March, several months prior to public disclosure. The attack is strictly local and requires initial code execution under a standard user account, making it relevant for shared or corporate environments. Security teams are advised to inventory Steam installations, apply application allowlisting, and monitor for anomalous SYSTEM-level processes linked to the service while awaiting an official patch.

Security NEXT•Vulnerabilities & Exploits

WatchGuard Fireware OS Affected by 15 Vulnerabilities Including Critical CVE-2026-86131

WatchGuard Technologies disclosed 15 vulnerabilities in Fireware OS, the operating system powering its UTM appliances. The advisories were published between September 29 and 30, 2026, covering issues that range from remote code execution and authorization bypass to file disclosure and denial of service. Impact varies by deployment, yet none of the flaws had been observed in active exploitation at disclosure time. The most severe finding, CVE-2026-86131 in BOVPN Over TLS, received a CVSS v4.0 base score of 9.2 and Critical rating. This code-injection flaw in client configuration handling allows an attacker who controls the VPN server to execute arbitrary commands with root privileges on the connecting Firebox device. The remaining vulnerabilities affect multiple components and are tracked under separate CVE identifiers listed in the official advisories.

Habr•Vulnerabilities & Exploits

Rust Researcher Builds AI Pipeline to Test 900 Vulnerability Hypotheses Across Crates and Linux Kernel

Sergey Gordeychik developed the rust-in-peace research harness that combines multiple LLM agents, traditional SAST tools, and dynamic verification to hunt for memory-safety, logic, and API misuse issues in Rust code. The system generates independent hypotheses, attempts to refute them with separate agents, then validates survivors through fuzzing, protocol tests, or container execution. Starting from the Damn Vulnerable Rust Application, the pipeline was expanded to popular crates including x509-parser, h2, and lopdf, ultimately producing a Linux kernel patch. Experiments showed that three parallel analysis passes yielded 20 confirmed findings after triage, with nine appearing in all passes. The work also highlighted how models can produce convincing but false positives when context such as dependency checks or call order is missing. Gordeychik presented the approach at ZeroNights under the title Rust in Peace: How to Raise Your Own Pet Mythos.

Security NEXT•Vulnerabilities & Exploits

Critical Zero-Day Vulnerability in FortiMail Allows Unauthenticated File Writes

Fortinet disclosed a critical zero-day vulnerability in its FortiMail email security product that is already being exploited in attacks. The flaw, tracked as CVE-2026-104286, affects the graphical user interface component and stems from improper sanitization of path traversal and NULL byte sequences. Attackers can craft malicious HTTP requests to write arbitrary files to the system without authentication. The vulnerability received a CVSS v3.1 base score of 9.8, classifying it as Critical. Fortinet discovered the issue internally but has also received reports of active exploitation. Planned patches include FortiMail 8.0.2, 7.6.7, and 7.4.9, while users on the 7.2 branch are advised to migrate to 7.4 or later.