Apache Tomcat
30 known vulnerabilities in Apache Tomcat, 11 critical, 6 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-34486 CVSS 7.5 high · actively exploited Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- CVE-2025-24813 CVSS 9.8 critical · actively exploited Apache Tomcat Path Equivalence Vulnerability
- CVE-2020-1938 CVSS 9.8 critical · actively exploited Apache Tomcat Improper Privilege Management Vulnerability
- CVE-2017-12617 CVSS 8.1 high · actively exploited Apache Tomcat Remote Code Execution Vulnerability
- CVE-2017-12615 CVSS 8.1 high · actively exploited Apache Tomcat on Windows Remote Code Execution Vulnerability
- CVE-2016-8735 CVSS 9.8 critical · actively exploited Apache Tomcat Remote Code Execution Vulnerability
Latest vulnerabilities
- CVE-2026-87022 CVSS 7.5 high Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when…
- CVE-2026-86350 CVSS 9.1 critical Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression…
- CVE-2026-86248 CVSS 9.8 critical CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This…
- CVE-2026-79677 CVSS 7.5 high Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of…
- CVE-2026-78437 CVSS 7.3 high Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from…
- CVE-2026-78383 CVSS 7.5 high Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP…
- CVE-2026-77791 CVSS 7.5 high Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This…
- CVE-2026-77762 CVSS 8.1 high Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an…
- CVE-2026-77756 CVSS 3.7 low Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the…
- CVE-2026-76183 CVSS 9.8 critical Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be…
- CVE-2026-75973 CVSS 7.3 high Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the…
- CVE-2026-73581 CVSS 6.5 medium Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs…
- CVE-2026-73180 CVSS 6.8 medium Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed…
- CVE-2026-68763 CVSS 7.5 high Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is…
- CVE-2026-68569 CVSS 8.1 high Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be…
- CVE-2026-68525 CVSS 9.1 critical Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that…
- CVE-2026-66422 CVSS 8.1 high Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within…
- CVE-2026-65927 CVSS 7.5 high Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the…
- CVE-2026-65905 CVSS 9.8 critical Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been…
- CVE-2026-65637 CVSS 9.8 critical Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from…
- CVE-2026-65183 CVSS 8.1 high Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised…
- CVE-2026-65182 CVSS 9.1 critical Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a…
- CVE-2026-66299 CVSS 5.3 medium Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from…
- CVE-2026-59084 CVSS 9.1 critical Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor…
- CVE-2026-34486 CVSS 7.5 high · actively exploited Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- CVE-2025-24813 CVSS 9.8 critical · actively exploited Apache Tomcat Path Equivalence Vulnerability
- CVE-2020-1938 CVSS 9.8 critical · actively exploited Apache Tomcat Improper Privilege Management Vulnerability
- CVE-2017-12617 CVSS 8.1 high · actively exploited Apache Tomcat Remote Code Execution Vulnerability
- CVE-2017-12615 CVSS 8.1 high · actively exploited Apache Tomcat on Windows Remote Code Execution Vulnerability
- CVE-2016-8735 CVSS 9.8 critical · actively exploited Apache Tomcat Remote Code Execution Vulnerability