Emerging Threat: (July 2026 Release) Apache Traffic Server Denial of Service and Access Control Bypass
The July 2026 Apache Traffic Server security release addresses a large batch of vulnerabilities across the proxy core and its plugin ecosystem, disclosed on July 29, 2026 and fixed in versions 9.2.15 and 10.1.4. Published counts of the batch differ. The Apache Traffic Server project describes the release as addressing 34 CVEs, while Belgium’s Centre for Cybersecurity puts the figure at 38 vulnerabilities.