Apache Tomcat DoS flaw patched
A remotely exploitable denial-of-service vulnerability in Apache Tomcat has been fixed across multiple version branches.
CERT-FR issued an advisory for a vulnerability in Apache Tomcat (CVE-2026-66299) that allows a remote attacker to cause a denial of service. The flaw affects Tomcat 9.0.x before 9.0.121, 10.1.x before 10.1.58, and 11.0.x before 11.0.25.
Apache released patched versions on 28 July 2026 addressing the issue across all three supported branches. No exploitation in the wild is reported; organizations running affected Tomcat versions should apply the vendor-provided updates referenced in the official security bulletins.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0940
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free