Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInter...
Apache Tomcat has reported multiple vulnerabilities affecting versions 9.x, 10.x, and 11.x, including CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, and CVE-2026-53434. These vulnerabilities could allow remote attackers to bypass security restrictions, exploit replay attacks, and generate incomplet...
SAP has issued its December security updates, fixing 14 vulnerabilities across various products, including three critical-severity flaws. The most severe, CVE-2025-42880, has a CVSS score of 9.9 and involves a code injection issue in SAP Solution Manager ST 720, allowing authenticated attackers to e...