A vulnerability was found in Apache HTTP Server up to 2.4.66 and classified as problematic. Affected by this issue is some unknown functionality of the component mod_auth_digest. The manipulation results in observable timing discrepancy.
This vulnerability is identified as CVE-2026-33006. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been classified as problematic. This affects an unknown part of the component mod_authn_socache. This manipulation causes null pointer dereference.
This vulnerability is tracked as CVE-2026-33007. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been rated as critical. This issue affects some unknown processing of the component Module. Performing a manipulation results in http response splitting.
This vulnerability is cataloged as CVE-2026-33523. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Apache HTTP Server up to 2.4.66. This vulnerability affects unknown code of the component mod_proxy_ajp. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-33857. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Apache HTTP Server up to 2.4.66. This issue affects some unknown processing. Executing a manipulation can lead to improper null termination.
This vulnerability appears as CVE-2026-34032. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Apache HTTP Server up to 2.4.66. The affected element is an unknown function of the component mod_md. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-29168. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been declared as critical. Impacted is the function ajp_msg_check_header. Executing a manipulation can lead to buffer overflow.
The identification of this vulnerability is CVE-2026-28780. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been declared as problematic. This vulnerability affects unknown code of the component mod_dav_lock/mod_dav_svn. Such manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2026-29169. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
Canadian telecom providers face mounting cyber threats from ransomware, SIM swapping, data breaches, and nation-state attacks targeting critical infrastructure.