Critical Vulnerability in Apache Tomcat
27 August 2026
Attackers can exploit a critical vulnerability in Apache Tomcat to bypass security constraints and gain unauthorised access to protected resources. Patch immediately.
Background
Apache Software Foundation has released security updates to address a critical vulnerability (CVE-2026-65182) affecting Apache Tomcat. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.1 out of 10.
Impact
Successful exploitation of this security constraint bypass vulnerability could allow an unauthenticated attacker to bypass security restrictions and gain unauthorised access to protected resources.
Affected Products
The vulnerability affects the following products:
Apache Tomcat versions 11.0.0-M1 through 11.0.24
Apache Tomcat versions 10.1.0-M1 through 10.1.57
Apache Tomcat versions 9.0.0.M1 through 9.0.120
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://lists.apache.org/thread/joosxvzc9b49ttj8lj0jw9mqt0ml767m
