Oracle Tomcat Security Fixes Address Critical Vulnerabilities

Oracle Tomcat Security Fixes Address Critical Vulnerabilities

First seen 28 Jul 2026, 15:16 UTC Linuxsecurity 87% similarity 70.5

Article Content

Browse articles
ThreatCluster

On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInterceptor. Other vulnerabilities include CVE-2026-34487, which exposes Kubernetes bearer tokens, and CVE-2026-34486, allowing bypass of EncryptInterceptor protections. The vulnerabilities affect users of Apache Tomcat, particularly those running versions 9.0.117 and 10.1.49. Users are advised to audit Linux privileges to limit potential compromise and escalation. The fixes are critical for maintaining data integrity and security across affected systems.

Key Points: • Oracle released security fixes for Tomcat versions 9 and 10 on July 28, 2026. • Critical vulnerabilities include CVE-2026-29146 and CVE-2026-24734, impacting data encryption. • Users are urged to audit Linux privileges to prevent potential exploitation.

ThreatCluster AI How this analysis works

Timeline

2025-04-29
Public exploit for CVE-2025-46701 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2025-08-13
CVE-2025-55668 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-17
CVE-2026-24734 published
A certificate revocation bypass vulnerability was disclosed, affecting Tomcat's OCSP response validation.
Linuxsecurity
2026-02-17
CVE-2025-66614 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-09
Multiple CVEs published
Several vulnerabilities, including CVE-2026-29146 and CVE-2026-34487, were disclosed affecting Tomcat's security.
Linuxsecurity
2026-04-09
CVE-2026-34487 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-09
CVE-2026-29145 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-09
CVE-2026-32990 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-09
CVE-2026-34483 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-09
CVE-2026-29146 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →