How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Apache (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Apache vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2026-34486 | Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 2026-08-04 | |
| CVE-2026-34197 | ActiveMQ | Apache ActiveMQ Improper Input Validation Vulnerability | 2026-04-16 | |
| CVE-2024-38475 | HTTP Server | Apache HTTP Server Improper Escaping of Output Vulnerability | 2025-05-01 | |
| CVE-2025-24813 | Tomcat | Apache Tomcat Path Equivalence Vulnerability | 2025-04-01 | |
| CVE-2024-45195 | OFBiz | Apache OFBiz Forced Browsing Vulnerability | 2025-02-04 | |
| CVE-2024-27348 | HugeGraph-Server | Apache HugeGraph-Server Improper Access Control Vulnerability | 2024-09-18 | |
| CVE-2024-38856 | OFBiz | Apache OFBiz Incorrect Authorization Vulnerability | 2024-08-27 | |
| CVE-2024-32113 | OFBiz | Apache OFBiz Path Traversal Vulnerability | 2024-08-07 | |
| CVE-2020-17519 | Flink | Apache Flink Improper Access Control Vulnerability | 2024-05-23 | |
| CVE-2023-27524 | Superset | Apache Superset Insecure Default Initialization of Resource Vulnerability | 2024-01-08 | |
| CVE-2023-46604 | ActiveMQ | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability | 2023-11-02 | ransomware |
| CVE-2023-33246 | RocketMQ | Apache RocketMQ Command Execution Vulnerability | 2023-09-06 | |
| CVE-2016-8735 | Tomcat | Apache Tomcat Remote Code Execution Vulnerability | 2023-05-12 | |
| CVE-2021-45046 | Log4j2 | Apache Log4j2 Deserialization of Untrusted Data Vulnerability | 2023-05-01 | ransomware |
| CVE-2022-33891 | Spark | Apache Spark Command Injection Vulnerability | 2023-03-07 | |
| CVE-2022-24706 | CouchDB | Apache CouchDB Insecure Default Initialization of Resource Vulnerability | 2022-08-25 | |
| CVE-2022-24112 | APISIX | Apache APISIX Authentication Bypass Vulnerability | 2022-08-25 | |
| CVE-2020-1956 | Kylin | Apache Kylin OS Command Injection Vulnerability | 2022-03-25 | |
| CVE-2017-12617 | Tomcat | Apache Tomcat Remote Code Execution Vulnerability | 2022-03-25 | |
| CVE-2017-12615 | Tomcat | Apache Tomcat on Windows Remote Code Execution Vulnerability | 2022-03-25 | ransomware |
| CVE-2013-2251 | Struts | Apache Struts Improper Input Validation Vulnerability | 2022-03-25 | |
| CVE-2020-1938 | Tomcat | Apache Tomcat Improper Privilege Management Vulnerability | 2022-03-03 | |
| CVE-2017-9791 | Struts 1 | Apache Struts 1 Improper Input Validation Vulnerability | 2022-02-10 | |
| CVE-2016-3088 | ActiveMQ | Apache ActiveMQ Improper Input Validation Vulnerability | 2022-02-10 | |
| CVE-2006-1547 | Struts 1 | Apache Struts 1 ActionForm Denial-of-Service Vulnerability | 2022-01-21 | |
| CVE-2012-0391 | Struts 2 | Apache Struts 2 Improper Input Validation Vulnerability | 2022-01-21 | |
| CVE-2020-11978 | Airflow | Apache Airflow Command Injection | 2022-01-18 | |
| CVE-2020-13927 | Airflow's Experimental API | Apache Airflow's Experimental API Authentication Bypass | 2022-01-18 | |
| CVE-2019-0193 | Solr | Apache Solr DataImportHandler Code Injection Vulnerability | 2021-12-10 | |
| CVE-2021-44228 | Log4j2 | Apache Log4j2 Remote Code Execution Vulnerability | 2021-12-10 | ransomware |
| CVE-2021-40438 | Apache | Apache HTTP Server-Side Request Forgery (SSRF) | 2021-12-01 | ransomware |
| CVE-2017-9805 | Struts | Apache Struts Deserialization of Untrusted Data Vulnerability | 2021-11-03 | |
| CVE-2021-42013 | HTTP Server | Apache HTTP Server Path Traversal Vulnerability | 2021-11-03 | ransomware |
| CVE-2021-41773 | HTTP Server | Apache HTTP Server Path Traversal Vulnerability | 2021-11-03 | ransomware |
| CVE-2019-0211 | HTTP Server | Apache HTTP Server Privilege Escalation Vulnerability | 2021-11-03 | |
| CVE-2016-4437 | Shiro | Apache Shiro Code Execution Vulnerability | 2021-11-03 | |
| CVE-2019-17558 | Solr | Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability | 2021-11-03 | |
| CVE-2020-17530 | Struts | Apache Struts Remote Code Execution Vulnerability | 2021-11-03 | |
| CVE-2017-5638 | Struts | Apache Struts Remote Code Execution Vulnerability | 2021-11-03 | ransomware |
| CVE-2018-11776 | Struts | Apache Struts Remote Code Execution Vulnerability | 2021-11-03 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.