CVE-2026-89282

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.

  • Published Sep 22, 2026
  • CVSS 9.1 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-89282 at the National Vulnerability Database