---
title: Critical Vulnerability in Certain Versions of Apache HTTP Server
description: Critical vulnerability in Apache HTTP Server 2.4.49 could let cyber actors execute arbitrary code. Immediate updates are recommended.
image: https://blog.voiceplus.com.au/hubfs/ACSC.png
---

[![header-logo-img](https://blog.voiceplus.com.au/hubfs/VoicePlus_2023_blog_assets/logo_header.png)](https://www.voiceplus.com.au/)

- [Home](https://www.voiceplus.com.au/)
- Solutions
  
   ENTERPRISE SERVICES [Integrated Managed Mobility & EndPoint Services](https://www.voiceplus.com.au/enterprise-services/integrated-managed-mobility-and-endpoint-services) [Telecom Expense Management & Optimisation](https://www.voiceplus.com.au/enterprise-services/telecom-expense-management-and-optimisation) [Device Lifecycle Management](https://www.voiceplus.com.au/enterprise-services/device-lifecycle-management) [Procurement & Support](https://www.voiceplus.com.au/enterprise-services/procurement-and-support) [Device Security & Application](https://www.voiceplus.com.au/enterprise-services/device-security-and-application) [Site, Branch & Site Connectivity](https://www.voiceplus.com.au/enterprise-services/site-branch-and-site-connectivity)
  
   ENTERPRISE OUTCOMES [Reduce Costs](https://www.voiceplus.com.au/solutions/reduce-costs) [Track Assets & Centralized Management](https://www.voiceplus.com.au/solutions/track-assets-and-centralized-management) [Security](https://www.voiceplus.com.au/solutions/security)
- [About Us](https://www.voiceplus.com.au/about-us)
- [Contact Us](https://www.voiceplus.com.au/contact-us)
- [Blog](https://blog.voiceplus.com.au/en-au)
- [Trust Centre](https://www.voiceplus.com.au/trust-centre)

# Critical Vulnerability in Certain Versions of Apache HTTP Server

![underline-img](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/underline.png?width=212&height=3&name=underline.png)

18 October 2021

[![Share on linkedin](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/linkedin-color.png?width=24&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.voiceplus.com.au/en-au/critical-vulnerability-in-certain-versions-of-apache-http-server?utm_medium=social&utm_source=linkedin) [![Share on twitter](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/twitter-color.png?width=24&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://blog.voiceplus.com.au/en-au/critical-vulnerability-in-certain-versions-of-apache-http-server?utm_medium=social&utm_source=twitter&url=https://blog.voiceplus.com.au/en-au/critical-vulnerability-in-certain-versions-of-apache-http-server?utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on facebook](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/facebook-color.png?width=24&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://blog.voiceplus.com.au/en-au/critical-vulnerability-in-certain-versions-of-apache-http-server?utm_medium=social&utm_source=facebook)

A vulnerability exists in Apache HTTP Server 2.4.49. A cyber actor could exploit this vulnerability to execute arbitrary code. Initial information also indicates that the vulnerability could also be used perform remote code execution under certain configurations. Affected Australian organisations should apply the available patch.

Alert status: CRITICAL

### Background /What has happened?

Vulnerabilities ([CVE-2021-41773](https://httpd.apache.org/security/vulnerabilities_24.html)) and [CVE-2021-42013](https://httpd.apache.org/security/vulnerabilities_24.html)) have been identified in Apache HTTP Server, one of the most commonly used web servers in Australia and globally across both Unix-based and Microsoft Windows environments. This vulnerability could allow a cyber actor to execute arbitrary code remotely or download sensitive files outside of the web server root. A cyber actor could use these vulnerabilities to install malware or otherwise control the affected host or download files containing credentials or other sensitive information. A new update has been released by the Apache Software Foundation (version 2.4.51) which addresses the vulnerabilities present in 2.4.49 and 2.4.50.

The Apache Software Foundation has identified that this vulnerability is actively being exploited.

### Mitigation / How do I stay secure?

Australian organisations who utilise Apache HTTP Server should review their patch level and update to the latest available version if required.

Further details on the vulnerability and software updates are available from the [Apache Software Foundation](https://httpd.apache.org/security/vulnerabilities_24.html).

### Assistance / Where can I go for help?

The ACSC is monitoring the situation and is able to provide assistance and advice as required. Organisations that have been impacted or require assistance can contact the ACSC via **1300 CYBER1 ([1300 292 371](tel:1300%20292%20371)).**

## Latest from the Blog

[![blog-featured](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus%20One%20Platform.png?width=226&height=226&name=VoicePlus%20One%20Platform.png)](https://blog.voiceplus.com.au/en-au/one-platform-every-endpoint-atrium-intune-laptop-management)

[VoicePlus Atrium — one platform managing mobiles, laptops, lifecycle, and Intune security under one roof ![arrow](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/arrownext.png?width=27&height=12&name=arrownext.png)](https://blog.voiceplus.com.au/en-au/one-platform-every-endpoint-atrium-intune-laptop-management)

[![blog-featured](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus%20Enterprise%20Governance1.png?width=226&height=226&name=VoicePlus%20Enterprise%20Governance1.png)](https://blog.voiceplus.com.au/en-au/enterprise-mobility-governance-what-it-looks-like)

[What Enterprise-Grade Mobility Governance Actually Looks Like ![arrow](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/arrownext.png?width=27&height=12&name=arrownext.png)](https://blog.voiceplus.com.au/en-au/enterprise-mobility-governance-what-it-looks-like)

[![blog-featured](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus%20ISO27001%20trust.png?width=226&height=226&name=VoicePlus%20ISO27001%20trust.png)](https://blog.voiceplus.com.au/en-au/beyond-the-badge-why-voiceplus-chose-the-hard-road-to-iso/iec-270012022)

[VoicePlus Achieves ISO/IEC 27001:2022: Why We Chose the Hard Road to Build Real Trust ![arrow](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/arrownext.png?width=27&height=12&name=arrownext.png)](https://blog.voiceplus.com.au/en-au/beyond-the-badge-why-voiceplus-chose-the-hard-road-to-iso/iec-270012022)

[![blog-featured](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus%20000%20BYOD%20Old%20Phones.png?width=226&height=226&name=VoicePlus%20000%20BYOD%20Old%20Phones.png)](https://blog.voiceplus.com.au/en-au/why-employers-must-act-on-emergency-calling-risks-triple-zero)

[Why Employers Must Act on Emergency-Calling Risks | Triple Zero ![arrow](https://blog.voiceplus.com.au/hs-fs/hubfs/VoicePlus_2023_blog_assets/arrownext.png?width=27&height=12&name=arrownext.png)](https://blog.voiceplus.com.au/en-au/why-employers-must-act-on-emergency-calling-risks-triple-zero)

3 Strategies to Reduce Telecom Cost

[Here's How](https://landing.voiceplus.com.au/en-au/3-strategies-to-reduce-telecom-cost)

![footer-logoimg](https://blog.voiceplus.com.au/hubfs/VoicePlus_2023_blog_assets/footerlogo.png)

VoicePlus is your independent managed mobility and endpoint specialist. We combine our experience and technology to secure cost savings and optimise productivity for clients seeking better business outcomes.

 The VoicePlus Companies acknowledges the Traditional owners of the lands on which we meet and work, both at our offices on Cammeraygal land and our locations across Australia. We pay our respects to Elders’ past, present and emerging and honour their living culture and custodianship.

Solutions

[Integrated Managed Mobility](https://www.voiceplus.com.au/services/managed-mobile-computer-services)

[Telecom Expense Management](https://www.voiceplus.com.au/services/telecom-expense-management)

[Device Lifecycle Management](https://www.voiceplus.com.au/services/device-lifecycle-management)

[Procurement & Support](https://www.voiceplus.com.au/services/procurement-and-support)

[Device Security & Application](https://www.voiceplus.com.au/services/device-security)

[Site, Branch & Site Connectivity](https://www.voiceplus.com.au/services/managed-endpoint) 

![seperator-img](https://blog.voiceplus.com.au/hubfs/VoicePlus_2023_blog_assets/seperator.png)

[Reduce Cost](https://www.voiceplus.com.au/enterprise-outcomes/cost-optimisation)

[Track Assets](https://www.voiceplus.com.au/enterprise-outcomes/cost-visibility)

[Security](https://www.voiceplus.com.au/services/device-security)

VoicePlus

[Privacy Policy](https://www.voiceplus.com.au/policies/privacy-policy)

[Modern Slavery](https://www.voiceplus.com.au/policies/modern-slavery-statement)

[Contact Us](https://www.voiceplus.com.au/contact-us)

[About Us](https://www.voiceplus.com.au/about-us)

[Trust Centre](https://www.voiceplus.com.au/trust-centre)

Find Us

[+61 2 9334 5600](tel:+61%202%209334%205600)

[customercare@voiceplus.com.au](mailto:customercare@voiceplus.com.au)

[VoicePlus Head Office Suite 902, 275 Alfred Street North Sydney, NSW 2060 Australia](https://goo.gl/maps/kaky2AuyRWgHJicT9)

[VoicePlus Branch Office Suite A, Floor 8, 152 Quay Street Auckland, AUK 1010 New Zealand](https://maps.app.goo.gl/78fGwdLFHfXHNN4h9)

[![twitter-img](https://blog.voiceplus.com.au/hubfs/VoicePlus_2023_blog_assets/twitter.png)](https://x.com/VoicePlusData1) [![linkedin-img](https://blog.voiceplus.com.au/hubfs/VoicePlus_2023_blog_assets/linkedin.png)](https://www.linkedin.com/company/voiceplus-data) [![fb-img](https://blog.voiceplus.com.au/hubfs/VoicePlus_2023_blog_assets/fb.png)](https://www.facebook.com/VoicePlusData)

![VoicePlus is ISO/IEC 27001:2022 Certified](https://www.voiceplus.com.au/assets/footer-photos/ISO-Certified-1.png "VoicePlus is ISO/IEC 27001:2022 Certified") ![VoicePlus is ISO/IEC 27001:2022 Certified](https://www.voiceplus.com.au/assets/footer-photos/jas-anz-logo.gif "VoicePlus is ISO/IEC 27001:2022 Certified")

---

Copyright © 2026. All Rights Reserved

![](https://blog.voiceplus.com.au/hubfs/raw_assets/public/Custom/page/VoicePlus_blog_2023_theme/icons8-settings-32.png)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Australian Cyber Security Centre",
    "url" : "https://blog.voiceplus.com.au/en-au/author/australian-cyber-security-centre"
  },
  "dateModified" : "2024-09-11T12:02:48.152Z",
  "datePublished" : "2021-10-18T12:25:57.000Z",
  "headline" : "Critical Vulnerability in Certain Versions of Apache HTTP Server",
  "image" : [ "https://blog.voiceplus.com.au/hubfs/ACSC.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.voiceplus.com.au/en-au/critical-vulnerability-in-certain-versions-of-apache-http-server",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.voiceplus.com.au/hubfs/voiceplus_logo.png"
    },
    "name" : "VoicePlus"
  }
}
```