Junglewise Threat Intelligence

CVE-2026-65637: Apache Tomcat improper input validation in incomplete fix

CVE-2026-65637 · Severity: critical · CVSS 9.8 · Published 2026-08-25

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely-used application server that hosts Java web applications. An improper input validation vulnerability stemming from an incomplete fix for a previous security issue could allow attackers to bypass protections and compromise the integrity or availability of hosted applications and services.

Technical details

This vulnerability is an improper input validation flaw in Apache Tomcat that arose from an incomplete fix to CVE-2026-32990. The issue affects Tomcat versions 11.0.20–11.0.24, 10.1.53–10.1.57, and 9.0.115–9.0.120. The vulnerability is exploitable via network attack without requiring authentication or special privileges. An attacker can leverage the insufficient input validation to bypass existing security controls and achieve unauthorized access or denial of service. Patches are available in versions 11.0.25, 10.1.58, and 9.0.121.

Affected products

  • Apache Tomcat 11.0.20–11.0.24, 10.1.53–10.1.57, 9.0.115–9.0.120

Timeline

  • 2026-08-25: disclosed

References

Related threats