Apache disclosed CVE-2026-43515, an improper-authorization flaw in Tomcat’s handling of security constraints. When multiple constraints specify an HTTP method for the same extension pattern, Tomcat may enforce only the first constraint, potentially allowing intended access restrictions to be applied incorrectly. The issue affects Tomcat 9.0.0.M1–9.0.117, 10.1.0-M1–10.1.54, and 11.0.0-M1–11.0.21; MITRE also lists legacy Tomcat 7.0.0–7.0.109 and 8.5.0–8.5.100 as affected.
Apache also fixed CVE-2026-41293, a low-severity HTTP/2 request-header validation issue that can cause unexpected behavior in applications relying on Servlet API header values being specification-compliant. Organizations should upgrade to Tomcat 9.0.118, 10.1.55, or 11.0.22 or later; unsupported releases should be retired or moved to a supported fixed version. Apache had separately disclosed CVE-2026-32990, identifying an incomplete prior fix for CVE-2025-66614.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-43513, an improper case-sensitivity handling vulnerability in Tomcat's LockOutRealm component. It affects Tomcat 7.0.0–7.0.109, 8.5.0–8.5.100, 9.0.0.M1–9.0.117, 10.1.0-M1–10.1.54, and 11.0.0-M1–11.0.21; upgrades to 9.0.118, 10.1.55, or 11.0.22 remediate the issue.
Apache disclosed moderate-severity CVE-2026-43515, an improper-authorization issue where only the first HTTP-method constraint may be enforced when multiple constraints apply to the same extension pattern. Apache recommended upgrades to Tomcat 11.0.22, 10.1.55, or 9.0.118; MITRE also listed affected Tomcat 7 and 8.5 versions.
Apache disclosed low-severity CVE-2026-41293, in which HTTP/2 request headers were not properly validated and could cause unexpected application behavior. Affected Tomcat releases were advised to upgrade to 11.0.22, 10.1.55, or 9.0.118 or later.
Apache Tomcat issued a security advisory for CVE-2026-32990, stating that the fix for CVE-2025-66614 was incomplete.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
lists.apache.org
Open sourcelists.apache.org
Open sourcecve.mitre.org
Open sourcelists.apache.org
Open sourcecve.mitre.org
Open sourcelists.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.