Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInter...
Apache Tomcat has reported multiple vulnerabilities affecting versions 9.x, 10.x, and 11.x, including CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, and CVE-2026-53434. These vulnerabilities could allow remote attackers to bypass security restrictions, exploit replay attacks, and generate incomplet...
Oracle has released an important update for Oracle Linux 10 addressing multiple vulnerabilities in Tomcat. The update resolves issues including directory traversal with possible remote code execution (CVE-2025-55752), rule bypass in the Rewrite Valve (CVE-2025-31651), and a denial of service (CVE-20...