Apache

Security Scorecard

Score

13F

Total CVEs

1,018

Patch Rate

12%

126 patched

Avg Response

521d

days to patch

Critical Gaps

20

exploitable, no detection

Severity Breakdown

Critical10
High57
Medium98
Low0

Patch Status

Patched126 (12%)
Partial/Workaround2 (0%)
Unpatched890 (87%)

CVEs (1,028)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-20963MS Office SharePoint Deserialization ExploitHigh8.8-Patched
CVE-2026-22817Hono JWT Verification FlawHigh8.2-Patched
CVE-2026-22695PNG Heap Buffer Over-readMedium6.1-Patched
CVE-2025-68493CVE-2025-68493High8.1-Patched
CVE-2026-22600OpenProject LFR VulnerabilityCritical9.1-Patched
CVE-2025-53477Apache Nimble NULL Pointer DereferenceHigh7.52dUnpatched
CVE-2025-62235Apache NimBLE Authentication BypassHigh8.1-Patched
CVE-2025-52435Apache NimBLE Data Transmission Without Encryption VulnerabilityHigh7.5-Patched
CVE-2026-0707Keycloak Header Parser VulnerabilityMedium5.3-Patched
CVE-2026-22244OpenMetadata SSTI VulnerabilityHigh7.2-Patched