<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache Vulnerabilities in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276750#M46161</link>
    <description>&lt;P&gt;Thanks..I will raise a TAC case, for a formal response.&lt;BR /&gt;&lt;BR /&gt;TAC have come back with the below:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-23918&lt;/STRONG&gt;&amp;nbsp;-&amp;nbsp;&lt;STRONG&gt;Not vulnerable&lt;/STRONG&gt;.&amp;nbsp; The vulnerability affects only Apache HTTP Server 2.4.66; the product ships with version 2.4.61, which is not in the affected range.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-29168 - &amp;nbsp;Not vulnerable.&lt;/STRONG&gt;&amp;nbsp;mod_md is not shipped with our images.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-24072 -&amp;nbsp;Not exploitable&lt;/STRONG&gt;. The product does not allow non-administrative users to author&amp;nbsp;.htaccess&amp;nbsp;files. Only the root/admin user has write access to the web tree, so there is no privilege boundary for the bug to cross. Additionally,&amp;nbsp;AllowOverride None&amp;nbsp;is configured, so&amp;nbsp;.htaccess&amp;nbsp;files would be ignored even if planted.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-29169 - Not exploitable&lt;/STRONG&gt;. mod_dav_lock is loaded as a default module but is not configured: no Dav directives and no DavGenericLockDB exist in the Apache configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33006 - Not exploitable.&lt;/STRONG&gt;&amp;nbsp;The product does not use HTTP Digest authentication.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33007 - Not exploitable&lt;/STRONG&gt;. The product is not configured as a forward proxy. The vulnerable code path requires a caching forward proxy configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33523 - Not exploitable.&lt;/STRONG&gt;&amp;nbsp;The product does not relay HTTP responses from untrusted or third-party backend servers.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-28780 - Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33857-&amp;nbsp;Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-34032-&amp;nbsp;Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-34059 -&amp;nbsp;Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;BR /&gt;&lt;BR /&gt;Additionally below will be updated as well soon:&lt;BR /&gt;&amp;nbsp;&lt;A href="https://urldefense.com/v3/__https:/support.checkpoint.com/results/sk/sk182900__;!!AaIhyw!tksAYbMNWdodizLg_YF4SJLnGhCRnlAKIj-btd0AaoiKZdGF3bItFXK3dHMhWGen8yMjM0eXhTz50GDytVG8$" target="_blank"&gt;sk182900 - Check Point response to Apache HTTP Server CVEs&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 18 May 2026 11:30:23 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2026-05-18T11:30:23Z</dc:date>
    <item>
      <title>Apache Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276697#M46154</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do Checkpoint have a response to the below Redhat CVEs yet?&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5a3" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-23918__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqvoo6fmu$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-23918__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQvOO6fmU$" rel="noreferrer noopener" aria-label="Link CVE-2026-23918" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-23918&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5a5" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-24072__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqorfjxfa$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-24072__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQOrFJxfA$" rel="noreferrer noopener" aria-label="Link CVE-2026-24072" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-24072&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5a7" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-28780__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqddqjxw0$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-28780__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQDdQJXw0$" rel="noreferrer noopener" aria-label="Link CVE-2026-28780" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-28780&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5a9" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-29168__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryq_eztwnc$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-29168__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQ_eZtWNc$" rel="noreferrer noopener" aria-label="Link CVE-2026-29168" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-29168&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5ab" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-29169__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqrvvok_m$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-29169__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQrVvoK_M$" rel="noreferrer noopener" aria-label="Link CVE-2026-29169" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-29169&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5ad" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-33006__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqfanfiww$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-33006__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQFANfiww$" rel="noreferrer noopener" aria-label="Link CVE-2026-33006" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-33006&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5af" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-33007__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqn9yyldk$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-33007__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQN9yYLDk$" rel="noreferrer noopener" aria-label="Link CVE-2026-33007" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-33007&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5ah" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-33523__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryq0okdptq$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-33523__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQ0OkdPtQ$" rel="noreferrer noopener" aria-label="Link CVE-2026-33523" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-33523&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5aj" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-33857__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqb0jgjwq$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-33857__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQB0jGJWQ$" rel="noreferrer noopener" aria-label="Link CVE-2026-33857" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-33857&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5al" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-34032__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryqt1piq_y$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-34032__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQt1piQ_Y$" rel="noreferrer noopener" aria-label="Link CVE-2026-34032" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-34032&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A id="menur5an" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" title="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/cve-2026-34059__;!!aaihyw!tpjyqndh9e_mtlsiysyf6xx2y_ljabunqsopid2juzyspg8pt0uhmfu6ygpxjwsm_zb01ryq4aquvfu$" href="https://urldefense.com/v3/__https:/vwgbmikvasd0006.vwguk.emea.vwg/tsc/search/cve/CVE-2026-34059__;!!AaIhyw!tPJYQNdH9e_MTLsIysYf6XX2Y_LjAbUnqsopId2JuZySpg8pt0UHMFU6ygPXjwSm_Zb01ryQ4AQUVFU$" rel="noreferrer noopener" aria-label="Link CVE-2026-34059" target="_blank"&gt;&lt;SPAN&gt;CVE-2026-34059&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 10:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276697#M46154</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2026-05-08T10:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276723#M46157</link>
      <description>&lt;P&gt;Most of these CVEs are for modules/functions we don't use in our implementation, as near as I can tell.&lt;BR /&gt;Having said that, if you're looking for an official answer, that'll require a TAC case.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 20:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276723#M46157</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-05-08T20:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Vulnerabilities</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276750#M46161</link>
      <description>&lt;P&gt;Thanks..I will raise a TAC case, for a formal response.&lt;BR /&gt;&lt;BR /&gt;TAC have come back with the below:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-23918&lt;/STRONG&gt;&amp;nbsp;-&amp;nbsp;&lt;STRONG&gt;Not vulnerable&lt;/STRONG&gt;.&amp;nbsp; The vulnerability affects only Apache HTTP Server 2.4.66; the product ships with version 2.4.61, which is not in the affected range.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-29168 - &amp;nbsp;Not vulnerable.&lt;/STRONG&gt;&amp;nbsp;mod_md is not shipped with our images.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-24072 -&amp;nbsp;Not exploitable&lt;/STRONG&gt;. The product does not allow non-administrative users to author&amp;nbsp;.htaccess&amp;nbsp;files. Only the root/admin user has write access to the web tree, so there is no privilege boundary for the bug to cross. Additionally,&amp;nbsp;AllowOverride None&amp;nbsp;is configured, so&amp;nbsp;.htaccess&amp;nbsp;files would be ignored even if planted.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-29169 - Not exploitable&lt;/STRONG&gt;. mod_dav_lock is loaded as a default module but is not configured: no Dav directives and no DavGenericLockDB exist in the Apache configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33006 - Not exploitable.&lt;/STRONG&gt;&amp;nbsp;The product does not use HTTP Digest authentication.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33007 - Not exploitable&lt;/STRONG&gt;. The product is not configured as a forward proxy. The vulnerable code path requires a caching forward proxy configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33523 - Not exploitable.&lt;/STRONG&gt;&amp;nbsp;The product does not relay HTTP responses from untrusted or third-party backend servers.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-28780 - Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-33857-&amp;nbsp;Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-34032-&amp;nbsp;Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CVE-2026-34059 -&amp;nbsp;Not exploitable&lt;/STRONG&gt;&amp;nbsp;- AJP module is shipped, but not loaded with default configuration. The product does not use the AJP protocol.&lt;BR /&gt;&lt;BR /&gt;Additionally below will be updated as well soon:&lt;BR /&gt;&amp;nbsp;&lt;A href="https://urldefense.com/v3/__https:/support.checkpoint.com/results/sk/sk182900__;!!AaIhyw!tksAYbMNWdodizLg_YF4SJLnGhCRnlAKIj-btd0AaoiKZdGF3bItFXK3dHMhWGen8yMjM0eXhTz50GDytVG8$" target="_blank"&gt;sk182900 - Check Point response to Apache HTTP Server CVEs&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 18 May 2026 11:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Apache-Vulnerabilities/m-p/276750#M46161</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2026-05-18T11:30:23Z</dc:date>
    </item>
  </channel>
</rss>

