SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-41920

CRITICAL · CVSS 9.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A critical improper access control vulnerability in Apache Traffic Server versions 9.0.0 to 9.1.14 and 10.0.0 to 10.1.3 allows unauthorized access to sensitive resources, potentially leading to data exposure or manipulation. Organizations using affected versions should prioritize upgrading to versions 9.1.15 or 10.1.4 to mitigate the risk of exploitation. Immediate action is essential for those managing web traffic and content delivery to protect their systems and data integrity.

CVE
CVE-2026-41920
Severity
CRITICAL
CVSS
9.3
EPSS
0.31%
Apache

Original NVD Description

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)