CVE-2026-89281

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

  • Published Sep 22, 2026
  • CVSS 8.4 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-89281 at the National Vulnerability Database