{"schema_version":1,"title":"Apache Tomcat vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 78 vulnerabilities in Apache Tomcat: 11 in the last 7 days and 31 in the last 90 days, 21 of them critical and 7 exploited in the wild. The most recent, CVE-2026-87022, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/tomcat","json_url":"https://junglewise.ai/threats/technologies/tomcat.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/tomcat","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":31,"all_time":78,"critical":21,"exploited":7,"last_7_days":11,"last_30_days":11,"last_90_days":31,"last_365_days":54},"latest":[{"cve":"CVE-2026-87022","cvss":7.5,"epss":0.0042,"slug":"cve-2026-87022-improper-handling-of-length-parameter-inconsistency-vulnerability","title":"Apache Tomcat WebSocket message smuggling in per-message-deflate","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:08.64+00:00","url":"https://junglewise.ai/threats/cve-2026-87022-improper-handling-of-length-parameter-inconsistency-vulnerability"},{"cve":"CVE-2026-86350","cvss":9.1,"epss":0.0031,"slug":"cve-2026-86350-inconsistent-interpretation-of-http-2-requests-http-request","title":"Apache Tomcat HTTP/2 request smuggling via header mix-up","severity":"critical","exploited":false,"published_at":"2026-09-23T12:17:08.35+00:00","url":"https://junglewise.ai/threats/cve-2026-86350-inconsistent-interpretation-of-http-2-requests-http-request"},{"cve":"CVE-2026-86248","cvss":9.8,"epss":0.0039,"slug":"cve-2026-86248-client-cert-authentication-does-not-fail-as-expected-for-some","title":"Apache Tomcat CLIENT_CERT authentication bypass when soft fail disabled","severity":"critical","exploited":false,"published_at":"2026-09-23T12:17:08.237+00:00","url":"https://junglewise.ai/threats/cve-2026-86248-client-cert-authentication-does-not-fail-as-expected-for-some"},{"cve":"CVE-2026-79677","cvss":7.5,"epss":0.0032,"slug":"cve-2026-79677-missing-release-of-resource-after-effective-lifetime-comparison","title":"Apache Tomcat WebSocket denial of service due to lost async write timeout","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:07.593+00:00","url":"https://junglewise.ai/threats/cve-2026-79677-missing-release-of-resource-after-effective-lifetime-comparison"},{"cve":"CVE-2026-78437","cvss":7.3,"epss":0.0026,"slug":"cve-2026-78437-incomplete-cleanup-vulnerability-in-apache-tomcat-allows-a","title":"Apache Tomcat incomplete cleanup denial of service in HTTP/2","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:07.34+00:00","url":"https://junglewise.ai/threats/cve-2026-78437-incomplete-cleanup-vulnerability-in-apache-tomcat-allows-a"},{"cve":"CVE-2026-78383","cvss":7.5,"epss":0.0038,"slug":"cve-2026-78383-allocation-of-resources-without-limits-or-throttling","title":"Apache Tomcat resource exhaustion in AJP connector","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:07.213+00:00","url":"https://junglewise.ai/threats/cve-2026-78383-allocation-of-resources-without-limits-or-throttling"},{"cve":"CVE-2026-77791","cvss":7.5,"epss":0.0053,"slug":"cve-2026-77791-uncontrolled-resource-consumption-vulnerability-in-apache-tomcat","title":"Apache Tomcat denial of service in WebSocket close message handling","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:06.927+00:00","url":"https://junglewise.ai/threats/cve-2026-77791-uncontrolled-resource-consumption-vulnerability-in-apache-tomcat"},{"cve":"CVE-2026-77762","cvss":8.1,"epss":0.0036,"slug":"cve-2026-77762-concurrent-execution-using-shared-resource-with-improper","title":"Apache Tomcat HTTP/2 trailer field injection race condition","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:06.8+00:00","url":"https://junglewise.ai/threats/cve-2026-77762-concurrent-execution-using-shared-resource-with-improper"},{"cve":"CVE-2026-76183","cvss":9.8,"epss":0.0039,"slug":"cve-2026-76183-authentication-bypass-by-alternate-name-vulnerability-in-apache","title":"Apache Tomcat authentication bypass in WebSocket endpoints","severity":"critical","exploited":false,"published_at":"2026-09-23T12:17:06.537+00:00","url":"https://junglewise.ai/threats/cve-2026-76183-authentication-bypass-by-alternate-name-vulnerability-in-apache"},{"cve":"CVE-2026-75973","cvss":7.3,"epss":0.0024,"slug":"cve-2026-75973-improper-authentication-vulnerability-in-apache-tomcat-when","title":"Apache Tomcat improper authentication in Jakarta Authentication","severity":"high","exploited":false,"published_at":"2026-09-23T12:17:06.41+00:00","url":"https://junglewise.ai/threats/cve-2026-75973-improper-authentication-vulnerability-in-apache-tomcat-when"},{"cve":"CVE-2026-73581","cvss":6.5,"epss":0.0012,"slug":"cve-2026-73581-improper-check-for-certificate-revocation-vulnerability-in-apache","title":"Apache Tomcat certificate revocation check bypass in TLS","severity":"medium","exploited":false,"published_at":"2026-09-23T12:17:06.287+00:00","url":"https://junglewise.ai/threats/cve-2026-73581-improper-check-for-certificate-revocation-vulnerability-in-apache"},{"cve":"CVE-2026-73180","cvss":6.8,"epss":0.0044,"slug":"cve-2026-73180-apache-tomcat-websocket-session-lifetime-violation","title":"Apache Tomcat WebSocket session lifetime violation","severity":"medium","exploited":false,"published_at":"2026-08-25T22:17:06.107+00:00","url":"https://junglewise.ai/threats/cve-2026-73180-apache-tomcat-websocket-session-lifetime-violation"},{"cve":"CVE-2026-68763","cvss":7.5,"epss":0.0074,"slug":"cve-2026-68763-apache-tomcat-resource-exhaustion-in-http-2-backlog-tracking","title":"Apache Tomcat resource exhaustion in HTTP/2 backlog tracking","severity":"high","exploited":false,"published_at":"2026-08-25T22:17:05.97+00:00","url":"https://junglewise.ai/threats/cve-2026-68763-apache-tomcat-resource-exhaustion-in-http-2-backlog-tracking"},{"cve":"CVE-2026-68569","cvss":8.1,"epss":0.0053,"slug":"cve-2026-68569-apache-tomcat-authentication-bypass-in-datasourcerealm","title":"Apache Tomcat authentication bypass in DataSourceRealm","severity":"high","exploited":false,"published_at":"2026-08-25T22:17:05.837+00:00","url":"https://junglewise.ai/threats/cve-2026-68569-apache-tomcat-authentication-bypass-in-datasourcerealm"},{"cve":"CVE-2026-68525","cvss":9.1,"epss":0.0064,"slug":"cve-2026-68525-apache-tomcat-form-authentication-authorization-bypass","title":"Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limi","severity":"critical","exploited":false,"published_at":"2026-08-25T22:17:05.7+00:00","url":"https://junglewise.ai/threats/cve-2026-68525-apache-tomcat-form-authentication-authorization-bypass"},{"cve":"CVE-2026-66422","cvss":8.1,"epss":0.0055,"slug":"cve-2026-66422-apache-tomcat-improper-authorization-in-security-role-ref","title":"Apache Tomcat improper authorization in security-role-ref","severity":"high","exploited":false,"published_at":"2026-08-25T22:17:05.56+00:00","url":"https://junglewise.ai/threats/cve-2026-66422-apache-tomcat-improper-authorization-in-security-role-ref"},{"cve":"CVE-2026-65927","cvss":7.5,"epss":0.0074,"slug":"cve-2026-65927-apache-tomcat-off-by-one-error-in-rewritevalve-n-flag","title":"Apache Tomcat off-by-one error in RewriteValve [N] flag","severity":"high","exploited":false,"published_at":"2026-08-25T22:17:05.433+00:00","url":"https://junglewise.ai/threats/cve-2026-65927-apache-tomcat-off-by-one-error-in-rewritevalve-n-flag"},{"cve":"CVE-2026-65905","cvss":9.8,"epss":0.0078,"slug":"cve-2026-65905-apache-tomcat-digest-authenticator-authentication-bypass","title":"Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made","severity":"critical","exploited":false,"published_at":"2026-08-25T22:17:05.303+00:00","url":"https://junglewise.ai/threats/cve-2026-65905-apache-tomcat-digest-authenticator-authentication-bypass"},{"cve":"CVE-2026-65637","cvss":9.8,"epss":0.0074,"slug":"cve-2026-65637-apache-tomcat-improper-input-validation-in-incomplete-fix","title":"Apache Tomcat improper input validation in incomplete fix","severity":"critical","exploited":false,"published_at":"2026-08-25T22:17:05.177+00:00","url":"https://junglewise.ai/threats/cve-2026-65637-apache-tomcat-improper-input-validation-in-incomplete-fix"},{"cve":"CVE-2026-65183","cvss":8.1,"epss":0.0046,"slug":"cve-2026-65183-apache-tomcat-toctou-race-condition-in-unix-domain-socket","title":"Apache Tomcat TOCTOU race condition in Unix domain socket creation","severity":"high","exploited":false,"published_at":"2026-08-25T22:17:05.05+00:00","url":"https://junglewise.ai/threats/cve-2026-65183-apache-tomcat-toctou-race-condition-in-unix-domain-socket"},{"cve":"CVE-2026-65182","cvss":9.1,"epss":0.0057,"slug":"cve-2026-65182-apache-tomcat-security-constraint-bypass","title":"Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a lo","severity":"critical","exploited":false,"published_at":"2026-08-25T22:17:04.9+00:00","url":"https://junglewise.ai/threats/cve-2026-65182-apache-tomcat-security-constraint-bypass"},{"cve":"CVE-2026-66299","slug":"cve-2026-66299-apache-tomcat-uncontrolled-resource-consumption-in-websocket-chat","title":"Apache Tomcat uncontrolled resource consumption in WebSocket chat example","severity":"info","exploited":false,"published_at":"2026-07-28T15:17:50.21+00:00","url":"https://junglewise.ai/threats/cve-2026-66299-apache-tomcat-uncontrolled-resource-consumption-in-websocket-chat"},{"cve":"CVE-2026-59084","slug":"cve-2026-59084-apache-tomcat-insufficient-documentation-in-encryptinterceptor","title":"Apache Tomcat insufficient documentation in EncryptInterceptor","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:41.607+00:00","url":"https://junglewise.ai/threats/cve-2026-59084-apache-tomcat-insufficient-documentation-in-encryptinterceptor"},{"cve":"CVE-2026-59083","slug":"cve-2026-59083-apache-tomcat-security-constraint-bypass-in-rewrite-valve","title":"Apache Tomcat security constraint bypass in rewrite valve","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:41.483+00:00","url":"https://junglewise.ai/threats/cve-2026-59083-apache-tomcat-security-constraint-bypass-in-rewrite-valve"},{"cve":"CVE-2026-55957","slug":"cve-2026-55957-apache-tomcat-authentication-bypass-in-jndirealm","title":"Apache Tomcat authentication bypass in JNDIRealm","severity":"info","exploited":false,"published_at":"2026-06-29T21:16:45.7+00:00","url":"https://junglewise.ai/threats/cve-2026-55957-apache-tomcat-authentication-bypass-in-jndirealm"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":4,"exploited":0,"vulnerabilities":10},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":3,"exploited":0,"vulnerabilities":11}],"related":[{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache Tomcat","slug":"tomcat","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"web-server","url":"https://junglewise.ai/threats/technologies/tomcat"},"most_severe":[{"cve":"CVE-2026-34486","cvss":7.5,"epss":0.0656,"slug":"cve-2026-34486-apache-tomcat-encryption-bypass-in-encryptinterceptor","title":"Apache Tomcat encryption bypass in EncryptInterceptor","severity":"critical","exploited":true,"published_at":"2026-04-09T20:16:25.063+00:00","url":"https://junglewise.ai/threats/cve-2026-34486-apache-tomcat-encryption-bypass-in-encryptinterceptor"},{"cve":"CVE-2023-44487","cvss":5.3,"epss":1,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"Multiple Vendors HTTP/2 denial of service via Rapid Reset attack","severity":"critical","exploited":true,"published_at":"2023-10-10T21:28:24+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"},{"cve":"CVE-2025-24813","cvss":3.1,"epss":0.9993,"slug":"cve-2025-24813-apache-tomcat-path-equivalence-vulnerability","title":"Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT","severity":"critical","exploited":true,"published_at":"2025-03-10T18:31:56+00:00","url":"https://junglewise.ai/threats/cve-2025-24813-apache-tomcat-path-equivalence-vulnerability"},{"cve":"CVE-2020-1938","cvss":3.1,"epss":0.9927,"slug":"cve-2020-1938-apache-tomcat-improper-privilege-management-vulnerability","title":"Improper Privilege Management in Tomcat","severity":"critical","exploited":true,"published_at":"2020-06-15T18:51:21+00:00","url":"https://junglewise.ai/threats/cve-2020-1938-apache-tomcat-improper-privilege-management-vulnerability"},{"cve":"CVE-2017-12617","cvss":3,"epss":0.9997,"slug":"cve-2017-12617-apache-tomcat-remote-code-execution-vulnerability","title":"Unrestricted Upload of File with Dangerous Type Apache Tomcat","severity":"critical","exploited":true,"published_at":"2022-05-14T01:07:15+00:00","url":"https://junglewise.ai/threats/cve-2017-12617-apache-tomcat-remote-code-execution-vulnerability"},{"cve":"CVE-2017-12615","cvss":3,"epss":0.9964,"slug":"cve-2017-12615-apache-tomcat-on-windows-remote-code-execution-vulnerability","title":"When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server","severity":"critical","exploited":true,"published_at":"2018-10-17T16:30:31+00:00","url":"https://junglewise.ai/threats/cve-2017-12615-apache-tomcat-on-windows-remote-code-execution-vulnerability"},{"cve":"CVE-2016-8735","cvss":3,"epss":0.9034,"slug":"cve-2016-8735-apache-tomcat-remote-code-execution-vulnerability","title":"Apache Tomcat Improper Access Control vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-13T01:14:52+00:00","url":"https://junglewise.ai/threats/cve-2016-8735-apache-tomcat-remote-code-execution-vulnerability"},{"cve":"CVE-2009-3555","cvss":9.8,"epss":0.8726,"slug":"cve-2009-3555-apache-tomcat-plaintext-injection-via-tls-renegotiation","title":"Apache Tomcat plaintext injection via TLS renegotiation","severity":"critical","exploited":false,"published_at":"2022-05-02T03:46:22+00:00","url":"https://junglewise.ai/threats/cve-2009-3555-apache-tomcat-plaintext-injection-via-tls-renegotiation"},{"cve":"CVE-2026-41293","cvss":9.8,"epss":0.0168,"slug":"cve-2026-41293-apache-tomcat-improper-input-validation-in-http-2-request-headers","title":"Apache Tomcat improper input validation in HTTP/2 request headers","severity":"critical","exploited":false,"published_at":"2026-05-12T16:16:17.553+00:00","url":"https://junglewise.ai/threats/cve-2026-41293-apache-tomcat-improper-input-validation-in-http-2-request-headers"},{"cve":"CVE-2026-43512","cvss":9.8,"epss":0.0133,"slug":"cve-2026-43512-apache-tomcat-authentication-bypass-in-digest-authentication","title":"Apache Tomcat authentication bypass in digest authentication","severity":"critical","exploited":false,"published_at":"2026-05-12T16:16:17.99+00:00","url":"https://junglewise.ai/threats/cve-2026-43512-apache-tomcat-authentication-bypass-in-digest-authentication"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}