Critical DoS Vulnerabilities in Apache Tomcat 11 Addressed

Critical DoS Vulnerabilities in Apache Tomcat 11 Addressed

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

On September 10, 2026, SUSE released an important security update for Apache Tomcat 11, addressing multiple vulnerabilities including CVE-2026-65182, CVE-2026-65183, and CVE-2026-66299. These vulnerabilities include issues such as a bypass of security constraints, TOCTOU problems with Unix Domain Sockets, and potential memory exhaustion attacks. The update affects various SUSE Linux Enterprise Server versions and openSUSE Leap 15.6. Attack vectors include HTTP/2 and WebSocket implementations, which could lead to denial-of-service conditions. Administrators are urged to apply the patches immediately to mitigate risks. The vulnerabilities were published on August 25, 2026, indicating a recent discovery and urgency in patching. The advisory emphasizes the importance of keeping systems updated to prevent exploitation.

Key Points: • SUSE released a critical update for Apache Tomcat 11 addressing 11 vulnerabilities. • Key vulnerabilities include potential DoS attacks and security constraint bypasses. • Affected systems include SUSE Linux Enterprise Server and openSUSE Leap 15.6.

Ask AI about this cluster

Timeline

2026-07-28
CVE-2026-66299 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
Multiple CVEs published
CVE-2026-65182, CVE-2026-65183, CVE-2026-65637, and others were disclosed, revealing significant vulnerabilities in Apache Tomcat.
Linuxsecurity
2026-08-25
CVE-2026-65927 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-65905 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-65182 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-65637 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-68525 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-65183 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-66422 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
SUSE advisory released
SUSE issued an advisory detailing the vulnerabilities and the importance of applying patches to affected systems.
Linuxsecurity