Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-33267Remote Code Execution in Apache Traffic Server

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

View on NVD

Analysis

Apache Traffic Server presenta una vulnerabilidad crítica de validación de entrada que permite a un atacante no autenticado comprometer totalmente el servidor. Este componente se utiliza habitualmente como proxy inverso y caché en infraestructuras de alto tráfico. Es fundamental actualizar a las versiones 9.2.15 o 10.1.4 para evitar posibles ataques de ejecución de código remoto.

Relevant roles

BackendCloudLinuxCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-20

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Published: 7/29/2026, 8:16:30 AM
Last modified: 7/29/2026, 8:16:30 AM

References

HomeEventsBlogResourcesCoursesTeam