Linuxsecurity Oracle Tomcat Security Fixes Address Critical Vulnerabilities
Article Content
- •Oracle released security fixes for Tomcat versions 9 and 10 on July 28, 2026.
- •Critical vulnerabilities include CVE-2026-29146 and CVE-2026-24734, impacting data encryption.
- •Users are urged to audit Linux privileges to prevent potential exploitation.
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInterceptor. Other vulnerabilities include CVE-2026-34487, which exposes Kubernetes bearer tokens, and CVE-2026-34486, allowing bypass of EncryptInterceptor protections. The vulnerabilities affect users of Apache Tomcat, particularly those running versions 9.0.117 and 10.1.49. Users are advised to audit Linux privileges to limit potential compromise and escalation. The fixes are critical for maintaining data integrity and security across affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track CVE-2019-17569 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…