Apache Tomcat Multiple Vulnerabilities
Release Date: 29 Sep 2026
Multiple vulnerabilities were identified in Apache
Tomcat. A remote attacker could exploit some of these vulnerabilities to
trigger denial of service condition, security restriction bypass and data
manipulation on the targeted system.
Impact
- Denial
of Service
- Data
Manipulation
- Security
Restriction Bypass
System / Technologies affected
- Apache
Tomcat version 9.0.0.M1 to 9.0.121
- Apache
Tomcat version 10.1.0-M1 to 10.1.59
- Apache
Tomcat version 11.0.0-M1 to 11.0.25
Solutions
Before installation of the software, please visit the
vendor web-site for more details.
Apply fixes issued by the vendor:
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.60
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.26
Vulnerability Identifier
- CVE-2026-73581
- CVE-2026-75973
- CVE-2026-76183
- CVE-2026-77756
- CVE-2026-77762
- CVE-2026-77791
- CVE-2026-78383
- CVE-2026-78437
- CVE-2026-79677
- CVE-2026-86248
- CVE-2026-86350
- CVE-2026-87022
Source
Related Link
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.60
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.26
沒有留言:
發佈留言