Apache HTTP/2 Vulnerability (CVE-2026-23918)

Incident Report for Hostek

Monitoring

We are aware of the recently disclosed Apache HTTP/2 vulnerability (CVE-2026-23918) affecting certain Apache configurations with HTTP/2 enabled.

Our actively maintained hosting infrastructure has already received the necessary security updates through normal update channels where applicable. For older or legacy systems that cannot immediately be upgraded, HTTP/2 mitigation steps are available.

At this time, we are not aware of any active exploitation affecting Hostek-managed infrastructure.

This vulnerability is applicable only to cPanel/Linux hosting customers, both Shared and VPS.

Additional details, impact information, and mitigation instructions can be found in the following knowledgebase article:
https://help.hostek.com/en/articles/14983250-critical-apache-http-2-vulnerability-cve-2026-23918

We will continue monitoring the situation and provide further updates if necessary.
Posted May 05, 2026 - 21:26 UTC
This incident affects: Customer Support.