CVE-2026-23918
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66.
CVSS
8.8
Alto
EPSS
49.7%
p99
KEV
—
Exploit Today
30
0-100
Publicado: 4 may 2026 · Última mod.: 15 jul 2026 · CWE-415 · CWE-1341
49.7%EPSS · 30 días49.7%
2026-08-122026-09-09
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- httpd.apache.orghttps://httpd.apache.org/security/vulnerabilities_24.html
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/05/04/19
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13938
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-23918
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2465304
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23918.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-875858.8 ALT9.7%
——3Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)21hCVE-2026-799077.8 ALT8.8%
——3Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.23hCVE-2026-819507.8 ALT36.7%
——11Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.1dCVE-2026-800808.8 ALT47.0%
——14Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-775048.8 ALT47.6%
——14Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-774939.8 CRÍ60.0%
——18Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.1d