Follow us
Breaking
Web Hosting

The Apache evolution from NCSA patches to 2026 dominance

Tracing Apache's history from Brian Behlendorf's 1995 NCSA patches to its current status, this overview examines the Apache Way governance and its 22.6% market share as of August 2026.

Share

The 1995 NCSA origins

Brian Behlendorf fixed bugs in the NCSA server in 1994 to support the HotWired website for Wired magazine. He and Cliff Skolnick organized a mailing list to coordinate other programmers. By February 1995, eight core contributors formed the Apache Group. They released version 0.6.2 in April 1995. The group released Apache 1.0 on December 1, 1995. The name "Apache" is a pun on the software being "a patchy server". Behlendorf suggested the name because he wanted something more romantic than the "cyber" or "spider" themes of that era. The NCSA server was the market leader until Rob McCool left the project.

In 1999, the group incorporated as a 501(c)(3) non-profit to protect individual volunteers from lawsuits and to ensure the projects could exist beyond the participation of any single person. The group included members like Ken Coar, Miguel Gonzales, Mark Cox, Lars Eilebrecht, Ralf S. Engelschall, Roy T. Fielding, Dean Gaudet, Ben Hyde, Jim Jagielski, Alexei Kosut, Martin Kraemer, Ben Laurie, Doug MacEachern, Aram Mirzadeh, Sameer Parekh, Cliff Skolnick, Marc Slemko, William Stoddard, Paul Sutton, and Randy Terbush.

The group grew.

In 2000, the group held the first ApacheCon conference. During that event, they introduced Apache version 2.0 Alpha 1 to the public. Robert Thau designed the new server architecture to be modular and easier to port.

Community and the Apache Way

The Apache Software Foundation follows a philosophy called "The Apache Way". This model prioritizes community over code. Each project has a Project Management Committee. These committees consist of active contributors who guide product releases. You know how vital community stability remains for open source. The foundation prevents corporations from buying influence. This meritocratic process is the subject of industry case studies and business school curricula.

New projects enter the Apache Incubator first. These "podlings" must transition all intellectual property to the ASF. They must also demonstrate that their contributor base remains diverse and not dominated by a single company. Once a project proves its resilience, the board grants graduation to Top-Level Project status. This process ensures that no single company controls a project roadmap. Today, more than 150 different projects exist under the foundation. More than 1,500 people have committed or contributed a patch.

The ASF acts as a 501(c)(3) charity. The Linux Foundation acts as a 501(c)(6) trade organization. The Linux Foundation gathers corporate giants to fund internet infrastructure like Kubernetes. The ASF prohibits pay-to-play governance. A company can donate millions, but they receive zero influence over technical direction. Only individual code contributors earn votes.

The ASF is a charity.

Market share and security in 2026

Apache holds a 22.6% market share of all websites as of August 2026. Nginx holds 31.4% of the market, while Microsoft IIS holds 6.08%. Apache requires much more memory than Nginx. For 10,000 concurrent connections, Apache Prefork uses 50 to 100 GB of RAM. Nginx uses only 50 to 100 MB for that same load. Apache uses a process-driven architecture with Multi-Processing Modules like Prefork, Worker, and Event. Nginx uses an event-driven, asynchronous, non-blocking architecture.

Server Type Memory Usage (10k Connections)
Nginx 50-100 MB
Apache Prefork 50-100 GB
Apache Event 2-5 GB

The June 8, 2026 release of Apache HTTP Server 2.4.68 fixed several security flaws. These flaws included CVE-2026-29167, CVE-2026-34355, and CVE-2026-42535. Users should upgrade to 2.4.68 to avoid these issues. Many vulnerabilities in 2.4.67 and earlier allow for unauthorized access or denial of service. Specifically, CVE-2026-44119 allows local .htaccess authors to read files with the privileges of the httpd user. CVE-2026-43951 causes an out-of-bounds read in merge_response_headers. CVE-2026-24072 allows privilege escalation via expressions in .htaccess. Finally, CVE-2026-23918 involves a double free and possible RCE on early reset in version 2.4.66.

Nginx leads the market.

Will the gap between Apache and Nginx widen further?

Share

Technewsdaily

Senior tech writer covering AI, gadgets and cybersecurity. Breaking down the news that matters, every day.