Security: CVE-2026-23918
Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
CMD de actualización por defecto
yum update ea-apache24* # or WHM → EasyApache 4 → Update
Lo que esto significa bajo una licencia de SharedLicense
Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel, Imunify360 software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel, Imunify360 under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.
Situation
Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Impact
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
We have also pushed out a patch for the following additional CVE’s:
- CVE-2026-24072
- CVE-2026-33006
- CVE-2026-28780
- CVE-2026-29168
- CVE-2026-29169
- CVE-2026-33007
- CVE-2026-33523
- CVE-2026-33857
- CVE-2026-34032
- CVE-2026-34059
You can find more information on all of the above in our Change Logs: Easy Apache 4 Change logs
Call to Action
AlmaLinux
Please run the following command to update Easy Apache 4:
# dnf clean all
# dnf makecache
# dnf -y update ea-apache*
Please run the following command to update Easy Apache 4:
# yum update ea-apache24 –enablerepo=cl-ea4-testing
Please run the following command to update Easy Apache 4:
# yum update ea-apache24 –enablerepo=imunify360-ea-php-hardened-beta
Ubuntu
Please run the following command to update Easy Apache 4:
# apt update
# apt install –only-upgrade “ea-apache24*”
Preguntas frecuentes
What is CVE-2026-23918?
Is CVE-2026-23918 being exploited in the wild?
How do I fix CVE-2026-23918?
Why does this advisory list several CVEs?
Referencias
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema