Apache Software Foundation
Coverage of Apache Software Foundation in the Nexus archive.
- Judge considers tossing Databricks patent suit under California anti-SLAPP law
Databricks argues its lawsuit against Acacia Research Group over patent royalties should not be dismissed under California's anti-SLAPP law, claiming the case benefits users of Apache-licensed software. The dispute centers on a patent (U.S. Patent No. 8,190,610) originally filed by Yahoo and later acquired by R2 Solutions, a subsidiary of Acacia. Judge Harold Kahn suggested the claims might fall under protected activity, emphasizing the public interest exception is critical to Databricks' defense.
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
The Apache Software Foundation has released security updates to address several vulnerabilities in the HTTP Server, including a severe flaw that could lead to remote code execution. The vulnerability, tracked as CVE-2026-23918, has a CVSS score of 8.8 and is described as a case of double free and possible RCE in the HTTP/2 protocol handling. This issue enables DoS and potential RCE.
- Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
A high-severity vulnerability (CVE-2026-34197) in Apache ActiveMQ Classic is being actively exploited, prompting CISA to add it to its KEV catalog with a CVSS score of 8.8. Federal civilian agencies are required to address the flaw immediately.
- ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
The ThreatsDay Bulletin highlights a hybrid P2P botnet, a 13-year-old Apache RCE vulnerability resurfacing, and 18 other security issues. The report emphasizes overlooked vulnerabilities, questionable security practices, and attackers exploiting trusted platforms.