Zurück zu den Sicherheitshinweisen

Security: CVE-2026-23918

Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.

Critical 8.8 CVSS
CloudLinux cPanel Imunify360

Standard-Update-Befehl

yum update ea-apache24*   # or WHM → EasyApache 4 → Update

Was das unter einer SharedLicense-Lizenz bedeutet

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel, Imunify360 software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel, Imunify360 under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.

This issue affects Apache HTTP Server: 2.4.66.

Impact

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

We have also pushed out a patch for the following additional CVE’s: 

You can find more information on all of the above in our Change Logs: Easy Apache 4 Change logs

Call to Action

AlmaLinux

Please run the following command to update Easy Apache 4: 

# dnf clean all

# dnf makecache

# dnf -y update ea-apache*

CloudLinux

Please run the following command to update Easy Apache 4: 

# yum update ea-apache24 –enablerepo=cl-ea4-testing

Imunify360

Please run the following command to update Easy Apache 4: 

# yum update ea-apache24 –enablerepo=imunify360-ea-php-hardened-beta

Ubuntu

Please run the following command to update Easy Apache 4: 

# apt update 

# apt install –only-upgrade “ea-apache24*”

Häufig gestellte Fragen

What is CVE-2026-23918?
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Is CVE-2026-23918 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 49.73% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-23918?
Update CloudLinux, cPanel, Imunify360 to the patched release.Then confirm the running version matches the patched release listed above.
Why does this advisory list several CVEs?
One vendor release fixed multiple vulnerabilities. This advisory covers CVE-2026-23918, CVE-2026-24072, CVE-2026-33006, CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059 — updating to the patched release resolves all of them at once.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen