CRITICAL 9.3 CVE-2026-102795 Published 2 Oct 2026

Apache Traffic Server Improper Access Control Vulnerability

Worried this affects your website?

Apache Traffic Server is affected by an Improper Access Control vulnerability.

The issue affects the following versions:

  • 9.0.0 through 9.2.14
  • 10.0.0 through 10.1.3

Users are recommended to upgrade to 9.2.15 or 10.1.4, which fixes the issue.

This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.

Reference: CVE-2026-102795 on NVD

← Back to Security News