CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Lets Attackers Crash Servers and Potentially Execute Remote Code
Apache patched CVE-2026-23918, a critical double-free vulnerability in HTTP/2 handling that enables denial-of-service and potential remote code execution. CVSS 8.8. Patch to 2.4.67 immediately.







