This update for apache2 fixes the following issues
* CVE-2026-23918: http2: double free and possible RCE on early reset
(bsc#1263957).
* CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr
(bsc#1263935).
* CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via
`ajp_msg_check_header()` (bsc#1264163).
* CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976).
* CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP
response (bsc#1264150).
* CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server
crash via malicious requests (bsc#1263956).
* CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977).
* CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest
authentication (bsc#1263955).
* CVE-2026-33007: NULL pointer dereference in `mod_authn_socache` allows
unauthenticated remote user to crash a child processes (bsc#1263954).
* CVE-2026-33523: HTTP response splitting...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2686=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2686=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2686=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2686=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2686=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2686=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch...
Read the Full Advisory* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* apache2-debugsource-2.4.66-150400.6.57.1
* apache2-worker-debuginfo-2.4.66-150400.6.57.1
* apache2-2.4.66-150400.6.57.1
* apache2-prefork-2.4.66-150400.6.57.1
* apache2-prefork-debuginfo-2.4.66-150400.6.57.1
* apache2-devel-2.4.66-150400.6.57.1
* apache2-utils-2.4.66-150400.6.57.1
* apache2-utils-debuginfo-2.4.66-150400.6.57.1
* apache2-worker-2.4.66-150400.6.57.1
* apache2-debuginfo-2.4.66-150400.6.57.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* apache2-doc-2.4.66-150400.6.57.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* apache2-debugsource-2.4.66-150400.6.57.1
* apache2-worker-debuginfo-2.4.66-150400.6.57.1
* apache2-2.4.66-150400.6.57.1
* apache2-prefork-2.4.66-150400.6.57.1
* apache2-prefork-debuginfo-2.4.66-150400.6.57.1
* apache2-devel-2.4.66-150400.6.57.1
* apache2-utils-2.4.66-150400.6.57.1
* apache2-utils-debuginfo-2.4.66-150400.6.57.1
*...
Read the Full Advisory* bsc#1207327
* bsc#1208708
* bsc#1214357
* bsc#1263935
* bsc#1263950
* bsc#1263951
* bsc#1263952
* bsc#1263953
* bsc#1263954
* bsc#1263955
* bsc#1263956
* bsc#1263957
* bsc#1264150
* bsc#1264163
* bsc#1267503
* bsc#1267955
* bsc#1267956
* bsc#1267962
* bsc#1267963
* bsc#1267965
* bsc#1267969
* bsc#1267970
* bsc#1267971
* bsc#1267972
* bsc#1267976
* bsc#1267977
* bsc#1267978
* bsc#690734
* jsc#PED-16334
## References:
* https://www.suse.com/security/cve/CVE-2006-20001.html
* https://www.suse.com/security/cve/CVE-2021-44224.html
* https://www.suse.com/security/cve/CVE-2021-44790.html
* https://www.suse.com/security/cve/CVE-2022-22719.html
* https://www.suse.com/security/cve/CVE-2022-22720.html
* https://www.suse.com/security/cve/CVE-2022-22721.html
* https://www.suse.com/security/cve/CVE-2022-23943.html
* https://www.suse.com/security/cve/CVE-2022-26377.html
* https://www.suse.com/security/cve/CVE-2022-28614.html
* https://www.suse.com/security/cve/CVE-2022-28615.html
* https://www.suse.com/security/cve/CVE-2022-29404.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.