Apache released Tomcat 11.0.25, 10.1.58, and 9.0.121 to remediate 11 vulnerabilities across supported release lines. The most consequential issues include CVE-2026-68569, where DataSourceRealm principal lookup can fail open with mechanisms such as CLIENT-CERT or SPNEGO; CVE-2026-65182, which can bypass security constraints based on path-rule ordering; and CVE-2026-65927, an off-by-one RewriteValve error that may bypass access controls. CVE-2026-68763 also permits denial of service through an HTTP/2 backlog-tracking allocation leak when streams are reset.
The updates additionally address authorization bypasses involving FORM-authentication redirects (CVE-2026-68525) and security-role-ref aliases (CVE-2026-66422), a limited DIGEST-authentication replay condition (CVE-2026-65905), an HTTP/2 strict-SNI-validation bypass from an incomplete prior fix (CVE-2026-65637), a Unix-domain-socket permission race (CVE-2026-65183), and WebSocket sessions that can survive expiration of their associated HTTP session (CVE-2026-73180). Organizations should prioritize upgrades, particularly for internet-facing deployments; Tomcat 7 and 8.5 installations are end of life and should be retired or otherwise remediated. No confirmed in-the-wild exploitation or public proof-of-concept code was reported.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed a low-severity flaw where a WebSocket session may remain active after its associated authenticated HTTP session ends if the HTTP session ID changed after WebSocket establishment. The behavior violates the Jakarta WebSocket specification and is fixed in 11.0.25, 10.1.58, and 9.0.121.
Apache announced an important uncontrolled-resource-consumption vulnerability caused by an allocation leak in HTTP/2 backlog tracking when a stream is reset. An attacker could use the flaw to cause denial of service; it is remediated in 11.0.25, 10.1.58, and 9.0.121.
Apache disclosed an important authentication flaw that can authenticate a user absent from the configured DataSourceRealm under configurations including CLIENT-CERT and SPNEGO. Apache released fixes in Tomcat 11.0.25, 10.1.58, and 9.0.121.
Apache disclosed a low-severity flaw where a redirect after FORM authentication can bypass a method-specific constraint, such as when a user is authorized for POST but not GET access to a resource. Apache fixed the issue in 11.0.25, 10.1.58, and 9.0.121.
Apache disclosed a low-severity authorization flaw in which security-role-ref definitions can be improperly treated as role aliases in Tomcat's Realm, potentially bypassing declarative role constraints. The issue was fixed in Tomcat 11.0.25, 10.1.58, and 9.0.121.
Apache addressed a flaw in the bundled WebSocket chat example that lets a slow WebSocket client cause unbounded message-buffer growth, potentially exhausting memory and crashing Tomcat. Deployments with the example applications removed are not affected.
Apache fixed an important RewriteValve off-by-one flaw where processing a restart using the [N] flag resumes at the second rule rather than the first. This behavior may bypass access controls dependent on correct rewrite-rule evaluation.
Apache addressed a low-severity DIGEST-authentication flaw that allows a captured request at the upper boundary of the nonce replay window to be replayed once while its nonce count remains valid. The fixes are included in Tomcat 11.0.25, 10.1.58, and 9.0.121.
Apache disclosed that an HTTP/2 request without an authority can bypass strict SNI validation because the prior fix for CVE-2026-32990 was incomplete. The moderate-severity issue affects specific recent Tomcat 11, 10.1, and 9 releases and is fixed in 11.0.25, 10.1.58, and 9.0.121.
Apache disclosed a low-severity TOCTOU race condition that can let an unauthorized local user access a Unix domain socket while Tomcat applies specific permissions. Fixed releases are 11.0.25, 10.1.58, and 9.0.121.
Apache disclosed an important improper-access-control flaw in which ordering a longer-path constraint before a restrictive shorter sub-path constraint can bypass the latter. The issue affects Tomcat 7 through 11 in the listed versions and is fixed in 11.0.25, 10.1.58, and 9.0.121.
Apache released Tomcat 11.0.25, 10.1.58, and 9.0.121 security updates addressing 11 reported vulnerabilities across supported release branches.
Apache released Tomcat 10.1.59, incorporating security fixes that had originally been included in the failed 10.1.58 release candidate. The release remediates the listed 2026 flaws for the Tomcat 10.1.x branch through version 10.1.57.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
27 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceseclists.org
Open sourcecve.mitre.org
Open sourcetomcat.apache.org
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.