[CIVN-2026-0440] Multiple Vulnerabilities in Apache Tomcat

By Published On: September 7, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Apache Tomcat


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Apache Tomcat 9.0.x versions 9.0.120 and prior

Apache Tomcat 10.1.x versions 10.1.57 and prior

Overview


Multiple vulnerabilities have been reported in Apache Tomcat that could allow an attacker to bypass authentication or security constraints, cause denial-of-service conditions, perform limited replay attacks, or gain unauthorized access on the targeted system.

 

Target Audience:

All end-user organizations and individuals using affected versions Apache Tomcat.


Risk Assessment:

High risk of unauthorized access to sensitive data, denial-of-service conditions, perform limited replay attacks.


Impact Assessment:

Potential for compromise of the affected system.


Description


Apache Tomcat is an open-source web server and servlet container that runs java-base web applications.


These vulnerabilities exist in Apache Tomcat due to improper handling of authentication and authorization, request handling, session management, and access-control mechanisms.


Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication or security constraints, cause denial-of-service conditions, perform limited replay attacks, or gain unauthorized access on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://tomcat.apache.org/security-9.html



Vendor Information


Apache Tomcat

https://tomcat.apache.org/


References


Apache Tomcat

https://tomcat.apache.org/security-9.html


CVE Name

CVE-2026-73180

CVE-2026-68763

CVE-2026-68569

CVE-2026-68525

CVE-2026-66422

CVE-2026-66299

CVE-2026-65927

CVE-2026-65905

CVE-2026-65637

CVE-2026-65183

CVE-2026-65182




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe1hMACgkQ3jCgcSdc

ys+6lw//SUWz8Hujsq3gq7+9g0ZynwySlvUI8n+rBb79g4I0aQlSqEHJkt+NbEtQ

ivN6cToqcbymVtJAc8Xu3LrgcTXpBzLZ6pB1fkxMbOP6bW1jqB4/GlP+bQcWc/yt

tkLo3ZDXyuZt1TXczIrelqq2X958ukrtqWO7DtH/gvA9dl6bco0GKn6Z/1b8j6gv

Odcwq2/+BFiZGcZf6e7D9SFfI0GGtFc/wRoiupb9b2HT2AhNnG/ykpMn2Y73tsnK

WYkTuxo7XDDjfz8kXcXkFGSsRVqNuANvwmce5Qt+0IwRvwO9UriKhvttGWxAGsuf

BuumBQBG9rXV5/DOyrSphMczh6MoQjTngnSxhPp1Zi1efxPndLmqfyTzRmO8hABl

CR8846ukB2Qf30AOFhTFNrglcG0dZFYYSFsVrvrI4boKX/bJ+UM3wS/Qdk6jWDyu

ZMjEy5QQ9AK56i1EfEe5qSj/AtWtoorcD+JCqsJIV48CRaeDstHnaAllHHt1wGS4

8nnYjwquQ9XEq5arFQOCH8Dcn/Ora65TJuvkZq7HEG1OD+3jgf/EEAH6gFnmmJOi

8G9cXrbyijr3jujuXaFUHsjHzvyC8To+bCFQ4EWkqMcVdKPKfDCqmOc6yL+xdTVp

fYAwyswkb5p5oN1KTgtu2hLxCiFV85gL5THLupE9PgljWGBjTyg=

=nhFd

—–END PGP SIGNATURE—–

Share this article