Apache Tomcat 11.0.26 / 10.1.60 / 9.0.122: 12 flaws (WebSocket authz bypass CVE-2026-76183 CVSS 9.8; HTTP/2 mix-up CVE-2026-86350 9.1) — public 23 Sep
Apache Tomcat security pages (Fixed in 11.0.26 dated 15 September 2026; issues made public 23 September 2026) document twelve vulnerabilities across WebSocket, HTTP/2, AJP, CLIENT_CERT/OCSP, and TLS CRL handling. Highest ADP CVSS 3.1 scores on CVE.report: CVE-2026-76183 Important — WebSocket endpoint security-constraint bypass via request paths parsed as endpoint templates (9.8; AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; affects 11.0.0-M1–11.0.25); CVE-2026-86248 Moderate (Apache) / 9.8 ADP — CLIENT_CERT soft-fail OCSP incomplete fix under FFM (11.0.0-M14–11.0.25); CVE-2026-86350 Important — HTTP/2 request-header mix-up regression from CVE-2026-41293 fix (9.1; 11.0.22–11.0.25). Other public CVEs in the same train: CVE-2026-87022 WebSocket per-message-deflate smuggling (7.5); CVE-2026-78383 AJP DoS missing body (7.5); CVE-2026-77791 WebSocket close busy-wait DoS (7.5); CVE-2026-79677 async WebSocket write timeout DoS (7.5); CVE-2026-77762 HTTP/2 trailer injection race (8.1); CVE-2026-78437 HTTP/2 malformed-request DoS (7.3); CVE-2026-75973 Jakarta Authentication cross-context realm mix-up (7.3); CVE-2026-73581 OpenSSL/OpenSSL-FFM CRL ignore with keystore (6.5); CVE-2026-77756 Transfer-Encoding on HTTP/1.0 behind reverse proxy (3.7). Same CVE set fixed in Tomcat 10.1.60 and 9.0.122. Apache does not ship per-CVE binary patches — upgrade to a release that contains the fixes. No in-the-wild claim on the vendor pages reviewed this pass. Primary: Apache Tomcat 11 security page (Fixed in 11.0.26); wire: Cyber Security News 24 Sep 2026.
- Product
- Apache Tomcat (11.x / 10.1.x / 9.0.x)
- Versions
- Tomcat 11.0.0-M1 through 11.0.25 (narrower ranges per CVE); fixed 11.0.26 / 10.1.60 / 9.0.122
- CVSS
- (CVSS 3.1 ADP, CVE-2026-76183 / CVE-2026-86248); 9.1 (CVE-2026-86350)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade to Apache Tomcat 11.0.26, 10.1.60, or 9.0.122 (or later trains containing the fixes); prioritise internet-facing WebSocket, HTTP/2, and AJP connectors; verify OpenPGP/SHA-512 on downloads
Primary: Apache Tomcat 11 — Fixed in 11.0.26 (public 23 Sep 2026) · Vendor: Apache Tomcat — security-11.html · CVE: CVE-2026-76183, CVE-2026-86350, CVE-2026-86248, CVE-2026-41293, CVE-2026-87022, CVE-2026-78383, CVE-2026-77791, CVE-2026-79677, CVE-2026-77762, CVE-2026-78437, CVE-2026-75973, CVE-2026-73581, CVE-2026-77756 · Apache Tomcat 10 — Fixed in 10.1.60 (also 9.0.122 on security-9)
