Back to Security Advisories

Security: CVE-2026-23918

Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.

Critical
CloudLinux cPanel Imunify360

Default Update CMD

sudo /scripts/upcp --force

Situation

Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.

This issue affects Apache HTTP Server: 2.4.66.

Impact

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

We have also pushed out a patch for the following additional CVE’s: 

You can find more information on all of the above in our Change Logs: Easy Apache 4 Change logs

Call to Action

AlmaLinux

Please run the following command to update Easy Apache 4: 

# dnf clean all

# dnf makecache

# dnf -y update ea-apache*

Please run the following command to update Easy Apache 4: 

# yum update ea-apache24 –enablerepo=cl-ea4-testing

Please run the following command to update Easy Apache 4: 

# yum update ea-apache24 –enablerepo=imunify360-ea-php-hardened-beta

Ubuntu

Please run the following command to update Easy Apache 4: 

# apt update 

# apt install –only-upgrade “ea-apache24*”

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System