logo

Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update

ID: bb4a02b8-ca54-5344-9186-cea8ed4ce8e4

STIX ID: report--bb4a02b8-ca54-5344-9186-cea8ed4ce8e4

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Do Son

...
...

Apache Tomcat released a security advisory fixing 11 vulnerabilities (one High, ten unrated, with three labeled Important) that affect multiple Tomcat branches up through 11.0.24, 10.1.57, and 9.0.120; notable issues include an authentication bypass (CVE-2026-68569), a security-constraint bypass (CVE-2026-65182), and an HTTP/2 denial-of-service (CVE-2026-68763). No active exploitation has been confirmed in the advisory, but because Tomcat serves Java web applications widely, administrators are advised to apply updates immediately to 11.0.25, 10.1.58, or 9.0.121.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.