The Apache Software Foundation has released security updates addressing multiple vulnerabilities in Apache HTTP Server. A critical vulnerability tracked as CVE-2026-23918 with a CVSS score of 8.8 involves a double free error in HTTP/2 protocol handling that could enable remote code execution.
