Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apache Tomcat Patches Critical Security Vulnerabilities

Apache Tomcat Patches Critical Security Vulnerabilities

Posted on August 27, 2026 By CWS

The Apache Software Foundation has released critical updates for Apache Tomcat, an open-source Java servlet container, addressing several security vulnerabilities. These patches, included in version 11.0.25, are essential for maintaining the integrity and availability of systems utilizing Tomcat.

Key Vulnerabilities Addressed

On August 25, 2026, Apache disclosed multiple flaws, ranging from minor authentication issues to significant bugs that could allow attackers to bypass security measures or execute denial-of-service attacks. Users operating Tomcat versions 11.0.0-M1 through 11.0.24 are strongly encouraged to apply these updates immediately, especially those in enterprise, cloud, or Linux settings.

Among the most critical vulnerabilities is CVE-2026-65182, which involves a bypass of security constraints. This issue arises when a rule for a longer URL path is prioritized over stricter rules for shorter paths, potentially allowing unauthorized access to protected resources.

Authentication and Access Control Issues

A significant concern is CVE-2026-68569, which affects various authentication methods like CLIENT-CERT and SPNEGO. This flaw can lead to fail-open scenarios where non-existent users in the DataSourceRealm may still gain access, compromising identity verification.

Another vulnerability, CVE-2026-65927, involves an off-by-one error in the RewriteValve component, allowing crafted rewrite rules to bypass access controls. Additionally, CVE-2026-68525 demonstrates how FORM authentication redirects can circumvent method-specific constraints, potentially exposing resources intended to be restricted to POST requests.

Denial-of-Service and Resource Exhaustion

Tomcat’s HTTP/2 and WebSocket implementations also contained vulnerabilities that could lead to server crashes. CVE-2026-68763 involves an allocation leak in HTTP/2 backlog tracking, which attackers could exploit by resetting streams to exhaust server resources.

Similarly, CVE-2026-66299 affects the WebSocket chat example, where an unbounded message buffer could enable a slow client to cause continuous memory growth, ultimately crashing the Tomcat process. Notably, systems that have removed example applications following prior advice are not affected by this vulnerability.

Apache recommends upgrading to version 11.0.25 to mitigate these risks. The combination of access control and service disruption flaws presents significant risks of data exposure and service downtime, particularly for internet-facing deployments.

Ensure your Tomcat servers are secure by implementing these updates promptly, safeguarding your systems against potential exploitation of these vulnerabilities.

Cyber Security News Tags:Apache Tomcat, authentication flaws, Cybersecurity, denial of service, Java servlet, open source software, Patches, security vulnerabilities, Server Protection, software updates

Post navigation

Previous Post: Critical Next.js Flaws Allow Remote Code Execution

Related Posts

Rise of Advanced EDR Killers in Ransomware Attacks Rise of Advanced EDR Killers in Ransomware Attacks Cyber Security News
Evolution of DDoS Attacks Mitigation Strategies for 2025 Evolution of DDoS Attacks Mitigation Strategies for 2025 Cyber Security News
Resilient Tycoon2FA Phishing Platform Bounces Back Rapidly Resilient Tycoon2FA Phishing Platform Bounces Back Rapidly Cyber Security News
New Rust Based InfoStealer Extracts Sensitive Data from Chromium-based Browsers New Rust Based InfoStealer Extracts Sensitive Data from Chromium-based Browsers Cyber Security News
Malicious Game Cheats Give Hackers Remote Access to PCs Malicious Game Cheats Give Hackers Remote Access to PCs Cyber Security News
SpaceX Disabled 2,500+ Starlink Terminals Tied to Scam Centers in Myanmar SpaceX Disabled 2,500+ Starlink Terminals Tied to Scam Centers in Myanmar Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apache Tomcat Patches Critical Security Vulnerabilities
  • Critical Next.js Flaws Allow Remote Code Execution
  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apache Tomcat Patches Critical Security Vulnerabilities
  • Critical Next.js Flaws Allow Remote Code Execution
  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark