{"id":43236,"date":"2021-10-05T17:23:08","date_gmt":"2021-10-05T17:23:08","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32697\/Apache-Fixes-Actively-Exploited-Zero-Day-Vulnerability-Patch-Now.html"},"modified":"2021-10-05T17:23:08","modified_gmt":"2021-10-05T17:23:08","slug":"apache-fixes-actively-exploited-zero-day-vulnerability-patch-now","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/","title":{"rendered":"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" alt height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2021\/10\/05\/Apache_headpic.jpg?rand=386606630\" width=\"1600\"><\/p>\n<p>The Apache Software Foundation has released version 2.4.50 of the HTTP Web Server to address two vulnerabilities, one of which is an actively exploited path traversal and file disclosure flaw.<\/p>\n<p>The Apache HTTP Server is an open-source, cross-platform web server that is extremely popular for being versatile, robust, and free. As such, any vulnerability in the product has <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/undisclosed-apache-velocity-xss-vulnerability-impacts-gov-sites\/\" target=\"_blank\" rel=\"noopener\">widespread consequences<\/a>.<\/p>\n<p>The actively exploited zero-day vulnerability is tracked as <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-41773\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2021-41773<\/a> and it enables actors to map URLs to files outside the expected document root by launching a path traversal attack.<\/p>\n<p>Path traversal attacks involve sending requests to access backend or sensitive server directories that should be out of reach. Normally, these requests are blocked, but in this case, the filters are bypassed by using encoded characters (ASCII) for the URLs.<\/p>\n<p>Additionally, exploits of this flaw may lead to the leaking of the source of interpreted files such as CGI scripts.<\/p>\n<p>For the attack to work, the target has to run Apache HTTP Server 2.4.49, and also has to have the \u201crequire all denied\u201d access control parameter disabled. Unfortunately, this appears to be the default configuration.<\/p>\n<p>Earlier Apache Server versions or those having a different access configuration aren\u2019t vulnerable to this flaw.<\/p>\n<p>Since the disclosure of the vulnerability, security researchers have been able to reproduce the vulnerability and warned that admins should patch immediately<\/p>\n<blockquote class=\"twitter-tweet\" align=\"center\" readability=\"7.8595317725753\">\n<p dir=\"ltr\" lang=\"en\">We have reproduced the fresh CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.<\/p>\n<p>If files outside of the document root are not protected by &#8220;require all denied&#8221; these requests can succeed.<\/p>\n<p>Patch ASAP! <a href=\"https:\/\/t.co\/6JrbayDbqG\" rel=\"nofollow noopener\">https:\/\/t.co\/6JrbayDbqG<\/a> <a href=\"https:\/\/t.co\/AnsaJszPTE\" rel=\"nofollow noopener\">pic.twitter.com\/AnsaJszPTE<\/a><\/p>\n<p>\u2014 PT SWARM (@ptswarm) <a href=\"https:\/\/twitter.com\/ptswarm\/status\/1445376079548624899?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\">October 5, 2021<\/a><\/p><\/blockquote>\n<p>A Shodan search revealed that there are over a hundred thousand Apache HTTP Server 2.4.49 deployments online, many of which could be vulnerable to exploitation, so updating your software as soon as possible should be considered&nbsp;exigent.<\/p>\n<div>\n<figure class=\"image\"><img loading=\"lazy\" decoding=\"async\" alt height=\"459\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/Code%20and%20Details\/apache_number.jpg\" width=\"662\"><figcaption><strong>Apache HTTP Server 2.4.49 deployments, Source: Shodan<\/strong><\/figcaption><\/figure>\n<\/div>\n<p>The vulnerability was discovered and reported to Apache by security researcher Ash Daulton and the cPanel Security Team on September 29, 2021. Being an actively exploited flaw, the fix for it <a href=\"https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\" target=\"_blank\" rel=\"nofollow noopener\">came pretty quickly<\/a>.<\/p>\n<p>At this time it is not known how the vulnerability is being used in attacks. When we asked Apache for further information, they sent BleepingComputer the following statement:&nbsp;<\/p>\n<blockquote readability=\"10\">\n<p>As Apache HTTP Server 2.4.49 was only released a few weeks ago it&#8217;s likely many users will not have upgraded yet. If and how this issue&nbsp;can be exploited is highly dependent on how users will have configured the server. If you are using 2.4.49, it is recommended that you upgrade to the latest version instead of using access control configuration as a mitigation. On a default installation, an attacker could still use the flaw to obtain the source code of interpreted files like CGI scripts.<\/p>\n<\/blockquote>\n<p>The second&nbsp;vulnerability is <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-41524\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2021-41524<\/a>, a null pointer dereference detected during HTTP\/2 request processing. This flaw allows&nbsp;an attacker to perform a&nbsp;denial of service (DoS) attack on the server.<\/p>\n<p>This flaw too only exists in Apache Server version 2.4.49, but it\u2019s not under active exploitation. It was discovered three weeks ago, fixed late last month, and incorporated now in version 2.4.50.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32697\/Apache-Fixes-Actively-Exploited-Zero-Day-Vulnerability-Patch-Now.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":43237,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[9677],"class_list":["post-43236","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlineflawpatchzero-dayapache"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-05T17:23:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now\",\"datePublished\":\"2021-10-05T17:23:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/\"},\"wordCount\":532,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg\",\"keywords\":[\"headline,flaw,patch,zero day,apache\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/\",\"name\":\"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg\",\"datePublished\":\"2021-10-05T17:23:08+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg\",\"width\":1600,\"height\":900},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,flaw,patch,zero day,apache\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineflawpatchzero-dayapache\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/","og_locale":"en_US","og_type":"article","og_title":"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-10-05T17:23:08+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now","datePublished":"2021-10-05T17:23:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/"},"wordCount":532,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg","keywords":["headline,flaw,patch,zero day,apache"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/","url":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/","name":"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg","datePublished":"2021-10-05T17:23:08+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now.jpg","width":1600,"height":900},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,flaw,patch,zero day,apache","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineflawpatchzero-dayapache\/"},{"@type":"ListItem","position":3,"name":"Apache Fixes Actively Exploited Zero-Day Vulnerability, Patch Now"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=43236"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43236\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/43237"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=43236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=43236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=43236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}