CVE-2021-41773
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
9 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.39%
probability
This CVE has a 94.39% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroPath traversal & file disclosure vulnerability
Attack Intelligence
Google Project Zero
Discovered
Sept. 29, 2021
Patched
Oct. 4, 2021
Reported by
Ash Daulton along with the cPanel Security Team
Root Cause Analysis
???
Exploits & PoC
blasty/CVE-2021-41773
CVE-2021-41773 playground
211
HightechSec/scarce-apache2
A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public
63
MrCl0wnLab/SimplesApachePathTraversal
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
62
iilegacyyii/PoC-CVE-2021-41773
PoC CVE-2021-41773 — iilegacyyii/PoC-CVE-2021-41773
52
lorddemon/CVE-2021-41773-PoC
PoC CVE-2021-41773 — lorddemon/CVE-2021-41773-PoC
39
justakazh/mass_cve-2021-41773
MASS CVE-2021-41773
29
im-hanzou/apachrot
Apache (Linux) CVE-2021-41773/2021-42013 Mass Vulnerability Checker
22
7 repos — triés par ⭐
Rechercher sur GitHub ↗
Apache fixes actively exploited zero-day vulnerability, patch now
BleepingComputer
Oct 05, 2021
Apache HTTP Server Path Traversal & Remote Code Execution (CVE-2021-41773 & CVE-2021-42013)
Qualys
Oct 28, 2021
Apache emergency update fixes incomplete patch for exploited bug
BleepingComputer
Oct 07, 2021
Security Advisory 2021-054
CERT-EU
Oct 06, 2021
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
Qualys
Oct 07, 2022
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Signal Intelligence
Confidence
95%
EPSS
94.39%
Mentions
9
Last Seen
Oct 07, 2022
CNA Information
Analyst Note
CVE-2021-41773 is a well-documented path traversal vulnerability in Apache HTTP Server 2.4.49 with a HIGH CVSS score of 7.5, confirmed by Google Project Zero and documented in official CERT-EU security advisories. The vulnerability's impact on URL-to-file mapping outside configured directories with potential CGI execution makes it a confirmed, high-severity issue with clear exploitation pathways.
Threat Actors 6
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cron
apt_group
🇷🇺 RU
Kinsing
apt_group
🇷🇺 RU
TeamTNT
apt_group
🇩🇪 DE
Red October
apt_group
🇷🇺 RU
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026