SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-33267

CRITICAL · CVSS 10 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Traffic Server versions 9.2.0 to 9.2.14 and 10.1.0 to 10.1.3 are vulnerable due to an improper input validation flaw, which could allow attackers to execute arbitrary code or cause denial-of-service conditions. Organizations using these affected versions should prioritize upgrading to 9.2.15 or 10.1.4 to mitigate the critical risk associated with this vulnerability.

CVE
CVE-2026-33267
Severity
CRITICAL
CVSS
10
EPSS
0.38%
Apache

Original NVD Description

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)