Apache
Vendor:
First CVE: Mar 5, 2026 · Active for under a year
3
Total CVEs
More Total CVEs than 64% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Apache over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2026
4 months ago
Most Recent CVE
May 8, 2026
77 days ago
CVE Severity & Scoring
Apache3 CVEs
100%
All CVEs352,231 CVEs
45%
40%
11%
Critical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5081CRITICAL Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure.
Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the v | May 6, 2026 | 9.1 | 39 | NO | NO |
CVE-2013-10075CRITICAL Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a sessi | May 8, 2026 | 9.1 | 35 | NO | NO |
CVE-2025-40931CRITICAL Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id.
Apache::Session::Generate::MD5 generates session ids insecurely. The default session id g | Mar 5, 2026 | 9.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (3 CVEs).
Media Mentions
Signals from CVEs in this product scope (3 CVEs).
Top CNAs Publishing CVEs For Apache
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| \ | 3 | 9.1 | 0.4% | 0 | 0 |