| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Tomcat products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-73180 | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that a... | 6.8 | 275 | Neutral | No |
| Yes |
| CVE-2026-68763 | DoS (Denial of Service) org.apache.tomcat:tomcat-coyote Dependency in Jira Service Management Data Center | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-68569 | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRe... | 8.1 | 476 | Neutral | No | Yes |
| CVE-2026-68525 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. Th... | 9.1 | 632 | Neutral | No | Yes |
| CVE-2026-66422 | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isU... | 8.1 | 519 | Neutral | No | Yes |
| CVE-2026-66299 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89... | 7.5 | 124 | Neutral | No | Yes |
| CVE-2026-65927 | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affec... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-65905 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonc... | 9.8 | 588 | Neutral | No | Yes |
| CVE-2026-65637 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from... | 9.8 | 674 | Neutral | No | Yes |
| CVE-2026-65183 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue aff... | 8.1 | 482 | Neutral | No | Yes |
| CVE-2026-65182 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint ... | 9.1 | 611 | Neutral | No | Yes |
| CVE-2026-59084 | Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: ... | 7.3 | 568 | Neutral | No | Yes |
| CVE-2026-59083 | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0... | 9.1 | 568 | Neutral | No | Yes |
| CVE-2026-55957 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the corre... | 7.3 | 450 | Neutral | Yes | Yes |
| CVE-2026-55956 | Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This... | 6.5 | 259 | Neutral | No | Yes |
| CVE-2026-55955 | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.... | 6.5 | 216 | Neutral | No | Yes |
| CVE-2026-55276 | BASM (Broken Authentication & Session Management) Apache Tomcat Dependency in Jira Service Management Data Center and Server | 9.1 | 568 | Neutral | No | Yes |
| CVE-2026-53434 | MITM (Man-in-the-Middle) org.apache.tomcat:tomcat-coyote-ffm Dependency in Confluence Data Center | 9.1 | 568 | Neutral | No | Yes |
| CVE-2026-53404 | BASM (Broken Authentication & Session Management) Apache Tomcat Dependency in Jira Service Management Data Center and Server | 7.3 | 349 | Neutral | No | Yes |
| CVE-2026-50229 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.... | 6.1 | 266 | Neutral | Yes | Yes |