VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR Advisory: Multiple Apache Tomcat Vulnerabilities

routine vulnerability technology

CERT-FR reports multiple vulnerabilities in Apache Tomcat 9, 10.1, and 11.0 allowing denial of service, data integrity compromise, and security bypass; patches available.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Apache Tomcat affecting versions 9.0.x prior to 9.0.122, 10.1.x prior to 10.1.60, and 11.0.x prior to 11.0.26. The vulnerabilities collectively allow a remote attacker to cause denial of service, compromise data integrity, or bypass security policy mechanisms within affected Tomcat instances. Thirteen CVEs are referenced in the advisory, though the bulletin does not provide granular technical detail on each individual flaw's mechanism.

Apache has released fixed versions (9.0.122, 10.1.60, and 11.0.26) addressing these issues, with the vendor's own security bulletins dated 15 September 2026 providing the authoritative per-CVE breakdown. No evidence of active exploitation in the wild is mentioned in this advisory. Defenders running Apache Tomcat should prioritize identifying affected instances across their estate and apply the vendor-supplied patches according to their standard change management processes, referencing the Apache Tomcat security pages for version-specific details on each CVE.

Mentioned in this report

Vulnerabilities CVE-2026-34500CVE-2026-41293CVE-2026-73581CVE-2026-75973CVE-2026-76183CVE-2026-77756CVE-2026-77762CVE-2026-77791CVE-2026-78383CVE-2026-78437CVE-2026-79677CVE-2026-86248CVE-2026-86350CVE-2026-87022

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1218

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free