remote code execution

Breaking Technology

Apache patches critical HTTP/2 vulnerability after five-month delay during Iran conflict

CVE-2026-23918 sat fixed but unpublished for 145 days as US-Iran war escalated, leaving millions of servers exposed to remote code execution during peak geopolitical tension.

7 min read ·