Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInter...
Apache Tomcat has reported multiple vulnerabilities affecting versions 9.x, 10.x, and 11.x, including CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, and CVE-2026-53434. These vulnerabilities could allow remote attackers to bypass security restrictions, exploit replay attacks, and generate incomplet...
The Apache Software Foundation has disclosed two vulnerabilities affecting Apache Tomcat versions 9, 10, and 11. The more critical vulnerability, CVE-2025-55752, involves a directory traversal flaw that could lead to remote code execution. System administrators are advised to take immediate action t...
The Apache Software Foundation has announced two critical vulnerabilities, CVE-2025-55752 and CVE-2025-55754, affecting Apache Tomcat versions 9, 10, and 11. CVE-2025-55752 is a directory traversal vulnerability that can lead to remote code execution, classified as 'Important' severity. System admin...