Skip to content
ThreatCluster

Multiple Vulnerabilities Discovered in Apache Tomcat

First seen 23 Sep 2026, 20:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 19:57 UTC
  • •Five critical vulnerabilities identified in Apache Tomcat.
  • •Affected versions range from 8.5.0 to 11.0.25.
  • •Immediate upgrades to 11.0.26, 10.1.60, or 9.0.122 recommended.

Five critical vulnerabilities have been identified in Apache Tomcat, affecting versions from 8.5.0 to 11.0.25. These include CVE-2026-77762, a race condition allowing HTTP/2 request injection; CVE-2026-78383, enabling denial of service via unauthenticated AJP requests; CVE-2026-77791, which allows DoS attacks through uncontrolled resource consumption; CVE-2026-78437, related to incomplete cleanup causing request failures; and CVE-2026-86350, a regression causing HTTP request smuggling. Users are advised to upgrade to the latest versions (11.0.26, 10.1.60, or 9.0.122) to mitigate these vulnerabilities. The vulnerabilities impact both supported and end-of-life versions of Apache Tomcat, posing significant risks to web applications relying on this server software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-05-12
CVE-2026-41293 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-23
CVE-2026-77762 published
Race condition vulnerability allows HTTP/2 request injection in Apache Tomcat.
Cve
2026-09-23
CVE-2026-78383 published
Denial of service vulnerability through unauthenticated AJP requests identified in Apache Tomcat.
Cve
2026-09-23
CVE-2026-77791 published
Uncontrolled resource consumption vulnerability in WebSocket close message allows DoS attacks.
Cve
2026-09-23
CVE-2026-78437 published
Incomplete cleanup vulnerability can cause request failures in Apache Tomcat.
Cve
2026-09-23
CVE-2026-86350 published
HTTP request smuggling vulnerability due to regression in previous fix identified in Apache Tomcat.
Cve

More articles in this cluster (5)

Following this threat?

Track CVE-2026-41293 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed