Linuxsecurity SUSE Releases Critical Security Patch for Tomcat 11 Addressing Multiple Vulnerabilities
Article Content
- •SUSE released a critical patch for Tomcat 11.0.18 on March 12, 2026.
- •The update addresses multiple vulnerabilities, including CVE-2025-66614 and CVE-2026-24734.
- •Affected systems include SUSE Linux Enterprise Server and openSUSE running Tomcat.
On March 12, 2026, SUSE issued a critical security update for Tomcat 11.0.18 to address several vulnerabilities, including CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734. The vulnerabilities include a client certificate verification bypass, improper input validation on HTTP/0.9 requests, and a certificate revocation bypass due to incomplete OCSP verification checks. These vulnerabilities could potentially allow attackers to exploit affected systems, leading to unauthorized access and data compromise. The update is crucial for users of SUSE Linux Enterprise Server and openSUSE, particularly those running web applications on Tomcat. Administrators are advised to apply the patches immediately using SUSE's recommended installation methods. The vulnerabilities were initially published between January and February 2026, highlighting the urgency of the patch. Failure to update could leave systems vulnerable to exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track CVE-2025-66614 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…