boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Apache

Vendor reference — Apache · sector: Open Source Ecosystems. Cumulative disclosure record across the archive.

Follow Apache — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs474436
KEV entries402
Rate & severity
KEV/100Med CVSSMed EPSSCHML
8.47.5.00498919014712

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▅

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-031
2026-049
2026-0521
2026-06121
2026-07181
2026-08102

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2021-4422810.0100.0CRITICALYES2021-12-10
CVE-2021-404389.0100.0CRITICALYES2021-12-01
CVE-2017-5638100.0YES2021-11-03
CVE-2013-2251100.0YES2022-03-25
CVE-2021-41773100.0YES2021-11-03
CVE-2018-11776100.0YES2021-11-03
CVE-2017-12617100.0YES2022-03-25
CVE-2024-45195100.0YES2025-02-04
CVE-2021-45046100.0YES2023-05-01
CVE-2021-42013100.0YES2021-11-03
CVE-2024-38475100.0YES2025-05-01
CVE-2025-24813100.0YES2025-04-01
CVE-2020-13927100.0YES2022-01-18
CVE-2023-46604100.0YES2023-11-02
CVE-2017-126158.199.9HIGHYES2022-03-25

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-348849.815.1CRITICAL2026-08-18
CVE-2026-736357.550.3HIGH2026-08-15
CVE-2026-736347.551.4HIGH2026-08-15
CVE-2026-736324.330.8MEDIUM2026-08-15
CVE-2026-736314.330.8MEDIUM2026-08-15
CVE-2026-736337.540.7HIGH2026-08-14
CVE-2026-662567.242.1HIGH2026-08-13
CVE-2026-689696.529.0MEDIUM2026-08-12
CVE-2026-689687.534.9HIGH2026-08-12
CVE-2026-592446.514.1MEDIUM2026-08-12
CVE-2026-580768.839.8HIGH2026-08-12
CVE-2026-689716.525.8MEDIUM2026-08-12
CVE-2026-675878.846.6HIGH2026-08-12
CVE-2026-650176.532.1MEDIUM2026-08-12
CVE-2026-732409.843.2CRITICAL2026-08-12

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Apache Traffic Server390
Apache Airflow360
Apache CXF260
Apache Thrift230
Apache Camel220
Apache ActiveMQ181
Apache HTTP Server151
Apache ActiveMQ All141
Apache Answer130
Apache IoTDB130
Apache Tomcat132
Apache APISIX120
Apache ActiveMQ Broker101
Apache Ranger100
Apache Fory90
Apache NiFi80
Apache Syncope80
Apache Qpid Broker-J70
Apache NimBLE60
Apache Qpid Proton Dotnet60
Apache Qpid Proton-J60
Apache Shiro60
Apache Allura50
Apache DolphinScheduler50
Apache JSPWiki50
Apache Kvrocks50
Apache MINA SSHD50
Apache Portable Runtime Utility50
Apache Qpid ProtonJ250
Apache Struts50
Struts55
Apache Gravitino40
Apache Lucy40
Apache Zeppelin40
HTTP Server44
Tomcat44
Apache Airflow FAB Provider30
Apache Airflow Google Provider30
Apache Fineract30
Apache Kylin30
Apache Kyuubi30
Apache Lucene.Net30
Apache Neethi30
OFBiz33
ActiveMQ22
Apache ActiveMQ Client20
Apache ActiveMQ Stomp20
Apache Atlas20
Apache HttpComponents Client20
Apache HttpComponents Core20
Apache Kerby20
Apache OFBiz20
Apache OpenNLP20
Apache Superset20
Apache Tika20
Apache Wicket20
Log4j222
Solr22
Struts 122

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-344862026-08-047.599.6HIGH
CVE-2026-341972026-04-168.899.9HIGH
CVE-2024-384752025-05-01100.0
CVE-2025-248132025-04-01100.0
CVE-2024-451952025-02-04100.0
CVE-2024-273482024-09-1899.9
CVE-2024-388562024-08-2799.9
CVE-2024-321132024-08-0799.9
CVE-2020-175192024-05-2399.9
CVE-2023-275242024-01-0899.9
CVE-2023-466042023-11-02100.0
CVE-2023-332462023-09-0699.9
CVE-2016-87352023-05-1299.8
CVE-2021-450462023-05-01100.0
CVE-2022-338912023-03-0799.8
CVE-2022-241122022-08-2599.9
CVE-2022-247062022-08-2599.8
CVE-2017-126152022-03-258.199.9HIGH
CVE-2013-22512022-03-25100.0
CVE-2017-126172022-03-25100.0
CVE-2020-19562022-03-2599.9
CVE-2020-19382022-03-0399.9
CVE-2016-30882022-02-1099.9
CVE-2017-97912022-02-1099.9
CVE-2012-03912022-01-2199.5

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-420132021-11-171736
CVE-2021-417732021-11-171736
CVE-2021-404382021-12-151708
CVE-2021-442282021-12-241699
CVE-2020-19382022-03-171616
CVE-2020-19562022-04-151587
CVE-2017-126172022-04-151587
CVE-2013-22512022-04-151587
CVE-2017-126152022-04-151587
CVE-2017-98052022-05-031569

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.