Multiple Vulnerabilities Discovered in Apache Tomcat
Article Content
- •Five critical vulnerabilities identified in Apache Tomcat.
- •Affected versions range from 8.5.0 to 11.0.25.
- •Immediate upgrades to 11.0.26, 10.1.60, or 9.0.122 recommended.
Five critical vulnerabilities have been identified in Apache Tomcat, affecting versions from 8.5.0 to 11.0.25. These include CVE-2026-77762, a race condition allowing HTTP/2 request injection; CVE-2026-78383, enabling denial of service via unauthenticated AJP requests; CVE-2026-77791, which allows DoS attacks through uncontrolled resource consumption; CVE-2026-78437, related to incomplete cleanup causing request failures; and CVE-2026-86350, a regression causing HTTP request smuggling. Users are advised to upgrade to the latest versions (11.0.26, 10.1.60, or 9.0.122) to mitigate these vulnerabilities. The vulnerabilities impact both supported and end-of-life versions of Apache Tomcat, posing significant risks to web applications relying on this server software.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-41293 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog products. These vulnerabilities pose significant risks due to active exploitation. Concurrently, IBM has…
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products On September 8, 2026, multiple CVEs were disclosed affecting various Microsoft products, including SharePoint and Office. Key vulnerabilities include improper access controls, buffer overflows, and command injections, which could allow unauthorized code execution and information disclosure. CVE-2026-85880, noted for…