Skip to content
Threat Feed

Product

HTTP Server

5 briefs RSS
low advisory

Detection of Web Server Reconnaissance via Error Log Spikes

This brief covers the detection of automated reconnaissance activities, such as vulnerability scanning and fuzzing, which manifest as significant spikes in web server error logs.

HTTP Server +2 reconnaissance web-security log-analysis
1r 3t
medium advisory

Detection of Web Server Access Log Deletion

Adversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.

HTTP Server +1 defense-evasion file-integrity logs cross-platform
1r 1t updated
high threat

Active Exploitation of Oracle HTTP Server and WebLogic Server Proxy Plug-in

CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities (KEV) Catalog due to confirmed in-the-wild exploitation of an improper access control vulnerability in Oracle HTTP and WebLogic proxy components.

exploited PoC Oracle HTTP Server +4
1c
critical advisory

Apache HTTP Server HTTP/2 Protocol Vulnerability Could Allow for Remote Code Execution

A vulnerability in Apache HTTP Server's HTTP/2 protocol can lead to denial of service by crashing worker processes, and in specific configurations (APR with mmap), remote code execution.

HTTP Server apache http2 rce dos webserver
2r 2t
critical threat

Multiple Vulnerabilities in Apache HTTP Server

Multiple vulnerabilities in Apache HTTP Server can be exploited by an attacker to gain elevated privileges, execute arbitrary code, bypass security measures, disclose sensitive information, or cause a denial-of-service condition.

HTTP Server apache vulnerability privilege-escalation execution defense-evasion information-disclosure denial-of-service
2r 6t