Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Apache
Vendor reference — Apache · sector: Open Source Ecosystems. Cumulative disclosure record across the archive.
Career totals
| All-time | YTD | |
|---|---|---|
| CVEs | 853 | 822 |
| KEV entries | 33 | 2 |
| KEV/100 | Med CVSS | Med EPSS | C | H | M | L |
|---|---|---|---|---|---|---|
| 3.9 | 7.5 | .0059 | 185 | 384 | 257 | 21 |
KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.
Monthly disclosures
Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▇▇█▅
| Month | New CVEs |
|---|---|
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 2 |
| 2026-03 | 2 |
| 2026-04 | 13 |
| 2026-05 | 24 |
| 2026-06 | 121 |
| 2026-07 | 181 |
| 2026-08 | 168 |
| 2026-09 | 195 |
| 2026-10 | 115 |
Notable CVEs
Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.
| CVE | CVSS | EPSS %ile | Severity | KEV | First seen |
|---|---|---|---|---|---|
| CVE-2021-44228 | 10.0 | 100.0 | CRITICAL | YES | 2021-12-10 |
| CVE-2017-5638 | 9.8 | 100.0 | CRITICAL | YES | 2017-03-11 |
| CVE-2021-40438 | 9.0 | 100.0 | CRITICAL | YES | 2021-12-01 |
| CVE-2021-41773 | 7.5 | 100.0 | HIGH | YES | 2021-10-05 |
| CVE-2018-11776 | 8.1 | 100.0 | HIGH | YES | 2018-08-22 |
| CVE-2024-45195 | 9.8 | 100.0 | CRITICAL | YES | 2024-09-04 |
| CVE-2021-45046 | 9.0 | 100.0 | CRITICAL | YES | 2021-12-14 |
| CVE-2017-12617 | 8.1 | 100.0 | HIGH | YES | 2017-10-03 |
| CVE-2021-42013 | 9.8 | 100.0 | CRITICAL | YES | 2021-10-07 |
| CVE-2024-38475 | 9.1 | 100.0 | CRITICAL | YES | 2024-07-01 |
| CVE-2025-24813 | 10.0 | 100.0 | CRITICAL | YES | 2025-03-10 |
| CVE-2024-32113 | 9.1 | 100.0 | CRITICAL | YES | 2024-05-08 |
| CVE-2023-46604 | 10.0 | 100.0 | CRITICAL | YES | 2023-10-27 |
| CVE-2017-12615 | 8.1 | 99.9 | HIGH | YES | 2022-03-25 |
| CVE-2024-38856 | 8.1 | 99.9 | HIGH | YES | 2024-08-05 |
Recent CVEs
| CVE | CVSS | EPSS %ile | Severity | KEV | First seen |
|---|---|---|---|---|---|
| CVE-2026-93684 | — | — | — | — | 2026-10-07 |
| CVE-2026-97720 | — | — | — | — | 2026-10-07 |
| CVE-2026-97146 | 4.8 | — | MEDIUM | — | 2026-10-07 |
| CVE-2026-90466 | — | — | — | — | 2026-10-07 |
| CVE-2026-92393 | 2.0 | — | LOW | — | 2026-10-07 |
| CVE-2026-78243 | 2.1 | — | LOW | — | 2026-10-07 |
| CVE-2026-94114 | 8.2 | — | HIGH | — | 2026-10-06 |
| CVE-2026-105242 | 5.3 | — | MEDIUM | — | 2026-10-06 |
| CVE-2026-105241 | 5.3 | — | MEDIUM | — | 2026-10-06 |
| CVE-2026-105243 | 5.3 | — | MEDIUM | — | 2026-10-06 |
| CVE-2026-105244 | 5.3 | — | MEDIUM | — | 2026-10-06 |
| CVE-2026-105239 | 5.3 | — | MEDIUM | — | 2026-10-06 |
| CVE-2026-105111 | 2.3 | — | LOW | — | 2026-10-06 |
| CVE-2026-105240 | 5.3 | — | MEDIUM | — | 2026-10-06 |
| CVE-2026-104714 | 8.8 | 6.6 | HIGH | — | 2026-10-05 |
Products
This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.
KEV entries
| CVE | KEV added | CVSS | EPSS %ile | Severity |
|---|---|---|---|---|
| CVE-2026-34486 | 2026-08-04 | 7.5 | 93.6 | HIGH |
| CVE-2026-34197 | 2026-04-16 | 8.8 | 96.7 | HIGH |
| CVE-2024-38475 | 2025-05-01 | 9.1 | 100.0 | CRITICAL |
| CVE-2025-24813 | 2025-04-01 | 10.0 | 100.0 | CRITICAL |
| CVE-2024-45195 | 2025-02-04 | 9.8 | 100.0 | CRITICAL |
| CVE-2024-27348 | 2024-09-18 | 9.8 | 99.9 | CRITICAL |
| CVE-2024-38856 | 2024-08-27 | 8.1 | 99.9 | HIGH |
| CVE-2024-32113 | 2024-08-07 | 9.1 | 100.0 | CRITICAL |
| CVE-2020-17519 | 2024-05-23 | 9.1 | 99.9 | CRITICAL |
| CVE-2023-27524 | 2024-01-08 | 8.9 | 99.9 | HIGH |
| CVE-2023-46604 | 2023-11-02 | 10.0 | 100.0 | CRITICAL |
| CVE-2023-33246 | 2023-09-06 | 9.8 | 99.9 | CRITICAL |
| CVE-2016-8735 | 2023-05-12 | 9.8 | 99.8 | CRITICAL |
| CVE-2021-45046 | 2023-05-01 | 9.0 | 100.0 | CRITICAL |
| CVE-2022-33891 | 2023-03-07 | 8.8 | 99.8 | HIGH |
| CVE-2022-24112 | 2022-08-25 | 9.8 | 99.9 | CRITICAL |
| CVE-2022-24706 | 2022-08-25 | 9.8 | 99.8 | CRITICAL |
| CVE-2017-12617 | 2022-03-25 | 8.1 | 100.0 | HIGH |
| CVE-2017-12615 | 2022-03-25 | 8.1 | 99.9 | HIGH |
| CVE-2020-1956 | 2022-03-25 | 8.8 | 99.9 | HIGH |
| CVE-2020-1938 | 2022-03-03 | 9.8 | 99.9 | CRITICAL |
| CVE-2017-9791 | 2022-02-10 | 9.8 | 99.9 | CRITICAL |
| CVE-2020-11978 | 2022-01-18 | 8.8 | 99.9 | HIGH |
| CVE-2021-44228 | 2021-12-10 | 10.0 | 100.0 | CRITICAL |
| CVE-2019-0193 | 2021-12-10 | 7.2 | 99.7 | HIGH |
KEV timing
| CVE | Days |
|---|---|
| CVE-2017-12615 | 0 |
| CVE-2021-40438 | 0 |
| CVE-2021-44228 | 0 |
| CVE-2026-34486 | 0 |
| CVE-2023-46604 | 6 |
| CVE-2026-34197 | 9 |
| CVE-2024-38856 | 22 |
| CVE-2025-24813 | 22 |
| CVE-2021-42013 | 27 |
| CVE-2021-41773 | 29 |
| CVE | Due | Days over |
|---|---|---|
| CVE-2021-42013 | 2021-11-17 | 1785 |
| CVE-2021-41773 | 2021-11-17 | 1785 |
| CVE-2021-40438 | 2021-12-15 | 1757 |
| CVE-2021-44228 | 2021-12-24 | 1748 |
| CVE-2020-1938 | 2022-03-17 | 1665 |
| CVE-2020-1956 | 2022-04-15 | 1636 |
| CVE-2017-12615 | 2022-04-15 | 1636 |
| CVE-2017-12617 | 2022-04-15 | 1636 |
| CVE-2019-0211 | 2022-05-03 | 1618 |
| CVE-2017-9805 | 2022-05-03 | 1618 |
Methodology
Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.
Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.
Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.