Apache Tomcat released security updates addressing several vulnerabilities across supported branches, including CVE-2026-59083, an incorrect URL decoding flaw in RewriteValve that can let attackers bypass security constraints in some configurations, and CVE-2026-59084, a documentation-related weakness that left EncryptInterceptor deployments without clearly defined secure configuration requirements. Apache said affected versions span Tomcat 11, 10.1, 9.0, and 8.5 releases, with some unsupported end-of-life versions potentially exposed as well.
Separate Tomcat advisories also described additional patched issues, including CVE-2026-53434, an invalid CRL configuration vulnerability rated CVSS 9.1, CVE-2026-50229, a cross-site scripting flaw in the Number Guess example, and other fixes tracked as CVE-2026-53404, CVE-2026-55276, CVE-2026-55955, and CVE-2026-55956. Organizations were urged to test and deploy updated releases, with Apache recommending upgrades to 11.0.24, 10.1.57, and 9.0.120 to remediate the newly disclosed issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-59084, a low-severity issue stemming from unclear documentation for securely configuring EncryptInterceptor across multiple Tomcat branches. Apache advised users to upgrade to 11.0.24, 10.1.57, or 9.0.120, and credited NDIx as the reporter.
Apache Tomcat disclosed CVE-2026-59083, a low-severity vulnerability in RewriteValve caused by incorrect URL hex decoding that may allow security constraint bypass in some configurations. Apache recommended upgrading to 11.0.24, 10.1.57, or 9.0.120.
On 2026-07-01, Apache Tomcat released a security update addressing multiple vulnerabilities, including CVE-2026-53434, CVE-2026-50229, CVE-2026-53404, CVE-2026-55276, CVE-2026-55955, and CVE-2026-55956. The issues included cross-site scripting and security restriction bypass risks, and organizations were advised to deploy the patch after testing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcelists.apache.org
Open sourceopenwall.com
Open sourceseclists.org
Open sourceegfincirt.org.eg
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcetomcat.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.