Apache disclosed multiple Tomcat vulnerabilities affecting supported 11.0.x, 10.1.x, and 9.0.x branches, including CVE-2026-43515, a moderate improper authorization flaw that can cause security constraints to be applied incorrectly when multiple method constraints define the same HTTP method for an extension, and CVE-2026-41284, a low-severity resource-consumption issue caused by unbounded reads in WebDAV LOCK and PROPFIND handling. Apache said the WebDAV flaw stems from missing request-body limits on methods accessible to unauthenticated users, and advised upgrades to 11.0.22, 10.1.55, or 9.0.118 to address the newly disclosed issues; older unsupported branches may also be affected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Atlassian said Jira Service Management Data Center and Server are affected by CVE-2026-34483, with the vulnerable Tomcat component introduced in version 11.3.0. It recommended upgrading to fixed supported releases including 11.3.5 or 10.3.20.
Apache disclosed CVE-2026-43515, a moderate improper authorization flaw where overlapping method constraints for the same extension could cause security constraints to be applied incorrectly. The company advised upgrading affected Tomcat installations to 11.0.22, 10.1.55, or 9.0.118.
Apache disclosed CVE-2026-41284, a low-severity unbounded read issue in WebDAV LOCK and PROPFIND handling caused by missing request body limits for unauthenticated methods. The advisory said affected Tomcat branches include 11.0.x, 10.1.x, and 9.0.x, and recommended upgrading to 11.0.22, 10.1.55, or 9.0.118.
Atlassian published an advisory stating that Jira Software Data Center and Server are affected by CVE-2026-34483, introduced in version 11.3.0. The company recommended upgrading to fixed supported releases including 11.3.5 or later and 10.3.20 or later.
Atlassian reported that CVE-2026-34483 affects Confluence Data Center and Server through its bundled Apache Tomcat dependency. It said affected Confluence versions span 8.9.0 through 10.2.0 and directed customers to upgrade to supported fixed releases including 10.2.11 and 9.2.20 or later.
Apache published a security advisory for CVE-2026-34483, an incomplete escaping flaw in Tomcat's JSON access logging component. The issue affects multiple Tomcat branches and was later referenced by downstream vendors as fixed in Tomcat 11.0.21, 10.1.54, and 9.0.117.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
jira.atlassian.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcelists.apache.org
Open sourcecve.mitre.org
Open sourcejira.atlassian.com
Open sourcejira.atlassian.com
Open sourcejira.atlassian.com
Open sourcejira.atlassian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.