Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On March 12, 2026, SUSE issued a critical security update for Tomcat 11.0.18 to address several vulnerabilities, including CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734. The vulnerabilities include a client certificate verification bypass, improper input validation on HTTP/0.9 requests, and a c...
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInter...
Apache Tomcat has reported multiple vulnerabilities affecting versions 9.x, 10.x, and 11.x, including CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, and CVE-2026-53434. These vulnerabilities could allow remote attackers to bypass security restrictions, exploit replay attacks, and generate incomplet...