CVE-2026-23918
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66.
CVSS
8.8
High
EPSS
49.7%
p99
KEV
—
Exploit Today
30
0-100
Published: May 4, 2026 · Last modified: Jul 15, 2026 · CWE-415 · CWE-1341
49.7%EPSS · 30 days49.7%
2026-08-122026-09-09
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- httpd.apache.orghttps://httpd.apache.org/security/vulnerabilities_24.html
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/05/04/19
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13938
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-23918
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2465304
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23918.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-875858.8 HIG9.7%
——3Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)20hCVE-2026-799077.8 HIG8.8%
——3Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.22hCVE-2026-819507.8 HIG36.7%
——11Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.23hCVE-2026-800808.8 HIG47.0%
——14Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-775048.8 HIG47.6%
——14Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-774939.8 CRI60.0%
——18Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.1d