< Back to situation

[REVISION HISTORY]

Apache Tomcat security vulnerabilities and exploitation

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-27 03:19 UTC → 2026-08-28 00:40 UTC · added removed

Security concerns regarding Apache Tomcat have intensified following reports of active exploitation and the discovery of multiple vulnerabilities. In early August 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified an encryption flaw, CVE-2026-34486, which allows attackers to bypass the EncryptInterceptor component. This vulnerability has been actively exploited by a Chinese-speaking threat actor to attempt the deployment of Java deserialization-based reverse shells. CISA urged organizations to patch affected versions of Apache Tomcat to prevent data exfiltration and credential theft. Later in August, the Apache Software Foundation released version 11.0.25 to address a dozen additional security vulnerabilities. These include important flaws such as CVE-2026-65182 and CVE-2026-68569, which could allow attackers to bypass authentication methods like CLIENT-CERT and SPNEGO. Other disclosed issues involve an off-by-one error in the RewriteValve component, flaws in FORM-based authentication, and bugs that could lead to denial-of-service conditions. By late August, the Apache Software Foundation released further patches addressing ten vulnerabilities in Apache Tomcat. These include important-rated flaws that could enable attackers to bypass security constraints or trigger denial-of-service conditions.

Versions

  1. 2026-08-28 00:40 UTC Apache Tomcat security vulnerabilities and exploitation
  2. 2026-08-27 03:19 UTC Apache Tomcat security vulnerabilities and exploitation

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.