Exploited CVEs / By vendor / Apache

Apache vulnerabilities actively exploited

40 Apache CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-34486 (Tomcat, added 2026-08-04). 8 of the 40 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

40 exploited CVEs8 ransomware-linked
Senserva AI Opinion and rich prompt for Apache exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Tomcat: 6 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-34486Tomcat2026-08-04CVSS 7.5, EPSS 83%
CVE-2025-24813Tomcat2025-04-01CVSS 9.8, EPSS 100%
CVE-2016-8735Tomcat2023-05-12CVSS 9.8, EPSS 90%
CVE-2017-12615Tomcat2022-03-25ransomware, CVSS 8.1, EPSS 100%
CVE-2017-12617Tomcat2022-03-25CVSS 8.1, EPSS 100%
CVE-2020-1938Tomcat2022-03-03CVSS 9.8, EPSS 99%

Struts: 5 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2013-2251Struts2022-03-25CVSS 9.8, EPSS 100%
CVE-2017-5638Struts2021-11-03ransomware, CVSS 9.8, EPSS 100%
CVE-2017-9805Struts2021-11-03CVSS 8.1, EPSS 99%
CVE-2018-11776Struts2021-11-03CVSS 8.1, EPSS 100%
CVE-2020-17530Struts2021-11-03CVSS 9.8, EPSS 96%

HTTP Server: 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-38475HTTP Server2025-05-01CVSS 9.1, EPSS 100%
CVE-2019-0211HTTP Server2021-11-03CVSS 7.8, EPSS 65%
CVE-2021-41773HTTP Server2021-11-03ransomware, CVSS 9.8, EPSS 100%
CVE-2021-42013HTTP Server2021-11-03ransomware, CVSS 9.8, EPSS 100%

ActiveMQ: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-34197ActiveMQ2026-04-16CVSS 8.8, EPSS 97%
CVE-2023-46604ActiveMQ2023-11-02ransomware, CVSS 9.8, EPSS 100%
CVE-2016-3088ActiveMQ2022-02-10CVSS 9.8, EPSS 99%

OFBiz: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-45195OFBiz2025-02-04CVSS 7.5, EPSS 100%
CVE-2024-38856OFBiz2024-08-27CVSS 9.8, EPSS 99%
CVE-2024-32113OFBiz2024-08-07CVSS 9.8, EPSS 99%

Other Apache products

CVEProductAdded to KEVSignals
CVE-2024-27348HugeGraph-Server2024-09-18CVSS 9.8, EPSS 99%
CVE-2020-17519Flink2024-05-23CVSS 7.5, EPSS 98%
CVE-2023-27524Superset2024-01-08CVSS 9.8, EPSS 97%
CVE-2023-33246RocketMQ2023-09-06CVSS 9.8, EPSS 97%
CVE-2021-45046Log4j22023-05-01ransomware, CVSS 9.0, EPSS 100%
CVE-2022-33891Spark2023-03-07CVSS 8.8, EPSS 93%
CVE-2022-24112APISIX2022-08-25CVSS 9.8, EPSS 96%
CVE-2022-24706CouchDB2022-08-25CVSS 9.8, EPSS 92%
CVE-2020-1956Kylin2022-03-25CVSS 8.8, EPSS 97%
CVE-2017-9791Struts 12022-02-10CVSS 9.8, EPSS 99%
CVE-2006-1547Struts 12022-01-21CVSS 7.5, EPSS 55%
CVE-2012-0391Struts 22022-01-21CVSS 9.8, EPSS 75%
CVE-2020-11978Airflow2022-01-18CVSS 8.8, EPSS 99%
CVE-2020-13927Airflow's Experimental API2022-01-18CVSS 9.8, EPSS 100%
CVE-2019-0193Solr2021-12-10CVSS 7.2, EPSS 84%
CVE-2021-44228Log4j22021-12-10ransomware, CVSS 10.0, EPSS 100%
CVE-2021-40438Apache2021-12-01ransomware, CVSS 9.0, EPSS 100%
CVE-2016-4437Shiro2021-11-03CVSS 9.8, EPSS 93%
CVE-2019-17558Solr2021-11-03CVSS 7.5, EPSS 99%

Common questions about exploited Apache CVEs

Which Apache vulnerabilities are actively exploited?

As of August 2026, 40 Apache CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Tomcat (6), Struts (5), HTTP Server (4), ActiveMQ (3). 8 are linked to ransomware campaigns.

What is the newest exploited Apache CVE?

CVE-2026-34486, affecting Tomcat, added to the CISA KEV catalog on 2026-08-04. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Apache CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Apache CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Apache KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.