# Apache Tomcat DoS flaw patched

Published: 2026-07-29 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/313a8cee-8637-532a-a4a3-adbe80e7af69/apache-tomcat-dos-flaw-patched

> A remotely exploitable denial-of-service vulnerability in Apache Tomcat has been fixed across multiple version branches.

CERT-FR issued an advisory for a vulnerability in Apache Tomcat (CVE-2026-66299) that allows a remote attacker to cause a denial of service. The flaw affects Tomcat 9.0.x before 9.0.121, 10.1.x before 10.1.58, and 11.0.x before 11.0.25.

Apache released patched versions on 28 July 2026 addressing the issue across all three supported branches. No exploitation in the wild is reported; organizations running affected Tomcat versions should apply the vendor-provided updates referenced in the official security bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-66299

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0940

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/313a8cee-8637-532a-a4a3-adbe80e7af69/apache-tomcat-dos-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
