boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Apache

Vendor reference — Apache · sector: Open Source Ecosystems. Cumulative disclosure record across the archive.

Follow Apache — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs853822
KEV entries332
Rate & severity
KEV/100Med CVSSMed EPSSCHML
3.97.5.005918538425721

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▇▇█▅

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-110
2025-120
2026-011
2026-022
2026-032
2026-0413
2026-0524
2026-06121
2026-07181
2026-08168
2026-09195
2026-10115

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2021-4422810.0100.0CRITICALYES2021-12-10
CVE-2017-56389.8100.0CRITICALYES2017-03-11
CVE-2021-404389.0100.0CRITICALYES2021-12-01
CVE-2021-417737.5100.0HIGHYES2021-10-05
CVE-2018-117768.1100.0HIGHYES2018-08-22
CVE-2024-451959.8100.0CRITICALYES2024-09-04
CVE-2021-450469.0100.0CRITICALYES2021-12-14
CVE-2017-126178.1100.0HIGHYES2017-10-03
CVE-2021-420139.8100.0CRITICALYES2021-10-07
CVE-2024-384759.1100.0CRITICALYES2024-07-01
CVE-2025-2481310.0100.0CRITICALYES2025-03-10
CVE-2024-321139.1100.0CRITICALYES2024-05-08
CVE-2023-4660410.0100.0CRITICALYES2023-10-27
CVE-2017-126158.199.9HIGHYES2022-03-25
CVE-2024-388568.199.9HIGHYES2024-08-05

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-93684————2026-10-07
CVE-2026-97720————2026-10-07
CVE-2026-971464.8—MEDIUM—2026-10-07
CVE-2026-90466————2026-10-07
CVE-2026-923932.0—LOW—2026-10-07
CVE-2026-782432.1—LOW—2026-10-07
CVE-2026-941148.2—HIGH—2026-10-06
CVE-2026-1052425.3—MEDIUM—2026-10-06
CVE-2026-1052415.3—MEDIUM—2026-10-06
CVE-2026-1052435.3—MEDIUM—2026-10-06
CVE-2026-1052445.3—MEDIUM—2026-10-06
CVE-2026-1052395.3—MEDIUM—2026-10-06
CVE-2026-1051112.3—LOW—2026-10-06
CVE-2026-1052405.3—MEDIUM—2026-10-06
CVE-2026-1047148.86.6HIGH—2026-10-05

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Apache Thrift840
Apache Airflow421
Apache Tomcat406
Apache Traffic Server400
Apache HTTP Server395
Apache Camel320
Apache Syncope300
Apache CXF260
Apache APISIX241
Apache ActiveMQ202
Apache CloudStack200
Apache Roller180
Apache ActiveMQ All151
Apache Struts155
Apache DolphinScheduler140
Apache Answer130
Apache IoTDB130
Apache MINA SSHD130
Apache Qpid Broker-J130
Apache NiFi120
Apache ActiveMQ Broker111
Apache Ranger110
Apache Wicket110
Apache Allura100
Apache InLong100
Apache Fory90
Apache ActiveMQ Artemis80
Apache Airflow FAB Provider80
Apache Artemis80
Apache Neethi80
Apache Shiro80
Apache Directory LDAP API70
Apache Impala70
Apache Karaf70
Apache Storm Nimbus70
Apache WSS4J70
Apache NimBLE60
Apache OpenNLP60
Apache Qpid Proton Dotnet60
Apache Qpid Proton-J60
Apache Log4net60
Apache Doris50
Apache JSPWiki50
Apache Kvrocks50
Apache OFBiz53
Apache Portable Runtime Utility50
Apache Qpid ProtonJ250
Apache Sling XSS50
Apache ZooKeeper50
Apache Airflow Google Provider40
Apache Camel K40
Apache Gravitino40
Apache PLC4X40
Apache Zeppelin40
Apache Fineract30
Apache Hive30
Apache Kylin30
Apache Kyuubi30
Apache Lucene.Net30
Apache Lucy30
Apache MINA30
Apache Nutch30
Apache Storm Client30
Apache Superset31
Apache Tomcat Native30
Apache XMLSchema30
Apache YuniKorn30
Apache ActiveMQ Client20
Apache ActiveMQ Stomp20
Apache Airflow Keycloak Provider20
Apache Airflow Teradata Provider20
Apache Atlas20
Apache Commons BCEL20
Apache HttpComponents Client20
Apache HttpComponents Core20
Apache Kerby20
Apache MyFaces20
Apache Polaris20
Apache SkyWalking20
Apache Sling Security Bundle20
Apache Solr21
Apache Spark21
Apache Storm UI20
Apache Storm Worker Launcher20
Apache Tika20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-344862026-08-047.593.6HIGH
CVE-2026-341972026-04-168.896.7HIGH
CVE-2024-384752025-05-019.1100.0CRITICAL
CVE-2025-248132025-04-0110.0100.0CRITICAL
CVE-2024-451952025-02-049.8100.0CRITICAL
CVE-2024-273482024-09-189.899.9CRITICAL
CVE-2024-388562024-08-278.199.9HIGH
CVE-2024-321132024-08-079.1100.0CRITICAL
CVE-2020-175192024-05-239.199.9CRITICAL
CVE-2023-275242024-01-088.999.9HIGH
CVE-2023-466042023-11-0210.0100.0CRITICAL
CVE-2023-332462023-09-069.899.9CRITICAL
CVE-2016-87352023-05-129.899.8CRITICAL
CVE-2021-450462023-05-019.0100.0CRITICAL
CVE-2022-338912023-03-078.899.8HIGH
CVE-2022-241122022-08-259.899.9CRITICAL
CVE-2022-247062022-08-259.899.8CRITICAL
CVE-2017-126172022-03-258.1100.0HIGH
CVE-2017-126152022-03-258.199.9HIGH
CVE-2020-19562022-03-258.899.9HIGH
CVE-2020-19382022-03-039.899.9CRITICAL
CVE-2017-97912022-02-109.899.9CRITICAL
CVE-2020-119782022-01-188.899.9HIGH
CVE-2021-442282021-12-1010.0100.0CRITICAL
CVE-2019-01932021-12-107.299.7HIGH

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-420132021-11-171785
CVE-2021-417732021-11-171785
CVE-2021-404382021-12-151757
CVE-2021-442282021-12-241748
CVE-2020-19382022-03-171665
CVE-2020-19562022-04-151636
CVE-2017-126152022-04-151636
CVE-2017-126172022-04-151636
CVE-2019-02112022-05-031618
CVE-2017-98052022-05-031618

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.