Apache HTTP Server
Apache Software Foundation · current 2.4.68
The current version of Apache HTTP Server is 2.4.68 (as of 08/07/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
- CVE-2024-38475Apache HTTP Server Improper Escaping of Output Vulnerability
9.1 critical · over the network, without login · CISA deadline was 22 May 25
- CVE-2019-0211Apache HTTP Server Privilege Escalation Vulnerability
7.8 high · locally only, with a basic account · CISA deadline was 3 May 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Apache HTTP Server: Mehrere Schwachstellen
WID-SEC-W-2026-1824 · 25 Aug
- Apache HTTP Server: Mehrere Schwachstellen
WID-SEC-W-2026-1354 · 21 Aug
- Apache HTTP Server: Mehrere Schwachstellen ermöglichen Manipulation von Daten
WID-SEC-W-2024-0801 · 20 Aug
- Apache HTTP Server: Mehrere Schwachstellen
WID-SEC-W-2024-1504 · 20 Aug
- Apache HTTP Server: Mehrere Schwachstellen
WID-SEC-W-2025-1529 · 20 Aug
- HTTP/2-Implementierungen: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2026-1791 · 14 Aug
- Apache HTTP Server: Mehrere Schwachstellen ermöglichen Denial of Service
WID-SEC-W-2023-2712 · 14 Aug
- Apache HTTP Server: Mehrere Schwachstellen
WID-SEC-W-2025-2750 · 14 Aug
Apache HTTP Server at a glance
The Apache HTTP Server is one of the most widely deployed web servers, embedded in countless stacks. The project ships coordinated security releases across supported branches; as an internet-facing server, httpd advisories (path traversal, request smuggling and the like) deserve prompt attention.
For admins httpd usually comes from the distribution, which backports fixes — for critical advisories, check that your system pulls the patched package and that the service is restarted. Keep the module set minimal, review the configuration for exposed defaults, and terminate TLS with current settings. Before larger version jumps, check module and configuration compatibility. Track the branch's support window, and mind bundled copies of httpd inside appliances that update on their own schedule.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 2.4 | 2.4.68 | supported |
| 2.2 | 2.2.34 | End of Life |
| 2.0 | 2.0.65 | End of Life |
| 1.3 | 1.3.42 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 2.4.68 | STABLE | 08/07/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Apache HTTP Server?
- Apache HTTP Server 2.4.68, released 08/07/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Apache HTTP Server release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Apache HTTP Server updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Apache HTTP Server update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Apache HTTP ServerEmbed this badge
Shows the current Apache HTTP Server version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/apache-httpd)https://patchletter.com/badge/apache-httpd.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).