Published on: 05 August 2026
The Apache Software Foundation released security updates to address multiple vulnerabilities in the Apache Tomcat. A remote attacker could exploit the vulnerabilities by sending a specially crafted request to the affected systems.
Reports indicated that an information disclosure vulnerability (CVE-2026-34486) is being exploited in the wild. System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
For detailed information of the affected systems, please refer to the corresponding security advisories at vendor's website.
Successful exploitation of the vulnerabilities could lead to information disclosure, security restriction bypass or tampering on an affected system.
The Apache Software Foundation has released new versions of the software to address the issues and they can be downloaded at the following URLs:
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.117
https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.54
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.21