uh.. So that's it, the apache server version? That's all? I looked at the critical cve's for that version, and honestly, they'd require a pretty specific setup to be abused if I understood them correctly. Most of them were various DoS with no information disclosure, and the only spooky one I saw require the server to have scripts the server is allowed to execute, but outside of the normal url mapping. Which then would have to be disclosing some info or doing something spooky. The rest seem to require the attacker to control the app behind the apache2 server.
Would be better to upgrade, of course, but it looks nowhere near as bad as the blog author makes it sound.