PULSE
FEED
ransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technologyransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technology
← All CVEs
CVE WatchOct 1, 2026

CVE-2026-93546

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker

CVSS

8.8

High

EPSS

0.3%

p25

KEV

—

Exploit Today

8

0-100

Published: Oct 1, 2026 · Last modified: Oct 1, 2026 · CWE-190

EPSS · 30d
0.3%EPSS · 30 days0.3%
2026-10-022026-10-04
Technical description

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-79113—
2.8%
——1OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.2d
CVE-2026-1036294.3 MED
6.7%
——2Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)2d
CVE-2026-1036214.3 MED
6.7%
——2Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)2d
CVE-2026-83632—
29.4%
——9Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.3d
CVE-2026-66837—
19.6%
——6Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.3d
CVE-2026-1025047.5 HIG
31.0%
——9Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.3d