CVE-2026-89281

Apache HTTP Server Project Apache Lounge Windows

Published 22 Sept 2026 · updated 23 Sept 2026 · Deferred

8.4 High · CVSS 3.1, CISA ADP

Description

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

References