Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update
ID: bb4a02b8-ca54-5344-9186-cea8ed4ce8e4
STIX ID: report--bb4a02b8-ca54-5344-9186-cea8ed4ce8e4
Feed Name: securityonline.info
Apache Tomcat released a security advisory fixing 11 vulnerabilities (one High, ten unrated, with three labeled Important) that affect multiple Tomcat branches up through 11.0.24, 10.1.57, and 9.0.120; notable issues include an authentication bypass (CVE-2026-68569), a security-constraint bypass (CVE-2026-65182), and an HTTP/2 denial-of-service (CVE-2026-68763). No active exploitation has been confirmed in the advisory, but because Tomcat serves Java web applications widely, administrators are advised to apply updates immediately to 11.0.25, 10.1.58, or 9.0.121.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
