APACHE HTTP Server has been updated to version 2.4.69 to fix 20 security flaws, with five rated as moderate or higher and one critical issue highlighted as mod_vhost_alias stack overflow. The advisory notes that there are no confirmed attacks in the wild at the time of the release. Notable CVEs include CVE-2026-63292 (mod_vhost_alias stack overflow) and several high‑severity flaws such as CVE-2026-57941 (mod_http2 use‑after‑free) and CVE-2026-59685 (Windows path overflow).
The package also covers WebDAV issues (CVE-2026-42528 and CVE-2026-93546) and other lower‑severity vulnerabilities, with the highest reported CVSSv3 score at 9.8 for several of the critical or high‑severity flaws. Most flaws date back to Apache 2.4.0, meaning many 2.4 installations could be affected, though Apache notes no exploitation in the wild.
Affected versions run from 2.4.0 up to 2.4.68 for most flaws, with CVE-2026-42356 limited to 2.4.60 through 2.4.68. To mitigate risks before upgrading, administrators are advised to keep LimitRequestFieldSize at the default when using mod_vhost_alias, disable unused modules (such as mod_dav, mod_heartmonitor and mod_proxy_ftp), restrict WebDAV write access to trusted users, and disable Digest authentication if unnecessary.
Organisations should apply Apache HTTP Server 2.4.69 promptly and monitor their Linux distribution backports for the fix. The article emphasises that, while no exploits are confirmed, rapid patching remains essential given the breadth of affected deployments.