CRITICAL 9.6 CVE-2026-66887 Published 15 Sept 2026

Apache HTTPD CGI Authorization Bypass

Worried this affects one of your servers?

The Apache HTTPD web server is affected by a vulnerability where state-changing CGI scripts can be accessed without proper authorization. The server does not perform session checks, allowing potential unauthorized access.

This issue affects Apache HTTPD versions 2.4.51 and earlier.

Reference: CVE-2026-66887 on NVD

← Back to Security News