Linuxsecurity
Oracle Tomcat Security Fixes Address Critical Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInterceptor. Other vulnerabilities include CVE-2026-34487, which exposes Kubernetes bearer tokens, and CVE-2026-34486, allowing bypass of EncryptInterceptor protections. The vulnerabilities affect users of Apache Tomcat, particularly those running versions 9.0.117 and 10.1.49. Users are advised to audit Linux privileges to limit potential compromise and escalation. The fixes are critical for maintaining data integrity and security across affected systems.
Key Points: • Oracle released security fixes for Tomcat versions 9 and 10 on July 28, 2026. • Critical vulnerabilities include CVE-2026-29146 and CVE-2026-24734, impacting data encryption. • Users are urged to audit Linux privileges to prevent potential exploitation.