Technology · Apache
Apache Tomcat vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 78 vulnerabilities in Apache Tomcat: 11 in the last 7 days and 31 in the last 90 days, 21 of them critical and 7 exploited in the wild. The most recent, CVE-2026-87022, was published on 23 September 2026.
- Last 7 days
- 11
- Last 90 days
- 31
- Critical, all time
- 21
- Exploited in the wild
- 7
Latest Apache Tomcat vulnerabilities
- CVE-2026-87022: Apache Tomcat WebSocket message smuggling in per-message-deflatehighCVSS 7.5EPSS 0.4%
- CVE-2026-86350: Apache Tomcat HTTP/2 request smuggling via header mix-upcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-86248: Apache Tomcat CLIENT_CERT authentication bypass when soft fail disabledcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-79677: Apache Tomcat WebSocket denial of service due to lost async write timeouthighCVSS 7.5EPSS 0.3%
- CVE-2026-78437: Apache Tomcat incomplete cleanup denial of service in HTTP/2highCVSS 7.3EPSS 0.3%
- CVE-2026-78383: Apache Tomcat resource exhaustion in AJP connectorhighCVSS 7.5EPSS 0.4%
- CVE-2026-77791: Apache Tomcat denial of service in WebSocket close message handlinghighCVSS 7.5EPSS 0.5%
- CVE-2026-77762: Apache Tomcat HTTP/2 trailer field injection race conditionhighCVSS 8.1EPSS 0.4%
- CVE-2026-76183: Apache Tomcat authentication bypass in WebSocket endpointscriticalCVSS 9.8EPSS 0.4%
- CVE-2026-75973: Apache Tomcat improper authentication in Jakarta AuthenticationhighCVSS 7.3EPSS 0.2%
- CVE-2026-73581: Apache Tomcat certificate revocation check bypass in TLSmediumCVSS 6.5EPSS 0.1%
- CVE-2026-73180: Apache Tomcat WebSocket session lifetime violationmediumCVSS 6.8EPSS 0.4%
- CVE-2026-68763: Apache Tomcat resource exhaustion in HTTP/2 backlog trackinghighCVSS 7.5EPSS 0.7%
- CVE-2026-68569: Apache Tomcat authentication bypass in DataSourceRealmhighCVSS 8.1EPSS 0.5%
- CVE-2026-68525: Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security…criticalCVSS 9.1EPSS 0.6%
- CVE-2026-66422: Apache Tomcat improper authorization in security-role-refhighCVSS 8.1EPSS 0.5%
- CVE-2026-65927: Apache Tomcat off-by-one error in RewriteValve [N] flaghighCVSS 7.5EPSS 0.7%
- CVE-2026-65905: Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-65637: Apache Tomcat improper input validation in incomplete fixcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-65183: Apache Tomcat TOCTOU race condition in Unix domain socket creationhighCVSS 8.1EPSS 0.5%
- CVE-2026-65182: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a…criticalCVSS 9.1EPSS 0.6%
- CVE-2026-66299: Apache Tomcat uncontrolled resource consumption in WebSocket chat exampleinfo
- CVE-2026-59084: Apache Tomcat insufficient documentation in EncryptInterceptorinfo
- CVE-2026-59083: Apache Tomcat security constraint bypass in rewrite valveinfo
- CVE-2026-55957: Apache Tomcat authentication bypass in JNDIRealminfo
Most severe Apache Tomcat vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34486: Apache Tomcat encryption bypass in EncryptInterceptorcriticalexploited in the wildCVSS 7.5EPSS 6.6%
- CVE-2023-44487: Multiple Vendors HTTP/2 denial of service via Rapid Reset attackcriticalexploited in the wildCVSS 5.3EPSS 100.0%
- CVE-2025-24813: Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTcriticalexploited in the wildCVSS 3.1EPSS 99.9%
- CVE-2020-1938: Improper Privilege Management in Tomcatcriticalexploited in the wildCVSS 3.1EPSS 99.3%
- CVE-2017-12617: Unrestricted Upload of File with Dangerous Type Apache Tomcatcriticalexploited in the wildCVSS 3EPSS 100.0%
- CVE-2017-12615: When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the servercriticalexploited in the wildCVSS 3EPSS 99.6%
- CVE-2016-8735: Apache Tomcat Improper Access Control vulnerabilitycriticalexploited in the wildCVSS 3EPSS 90.3%
- CVE-2009-3555: Apache Tomcat plaintext injection via TLS renegotiationcriticalCVSS 9.8EPSS 87.3%
- CVE-2026-41293: Apache Tomcat improper input validation in HTTP/2 request headerscriticalCVSS 9.8EPSS 1.7%
- CVE-2026-43512: Apache Tomcat authentication bypass in digest authenticationcriticalCVSS 9.8EPSS 1.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 7 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 2 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 10 | 4 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 11 | 3 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/tomcat.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apache Tomcat vulnerabilities", https://junglewise.ai/threats/technologies/tomcat, 26 September 2026.