# CERT-FR Advisory: Multiple Apache Tomcat Vulnerabilities

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/36825aa7-83ac-5886-81b6-256ed6feb71a/cert-fr-advisory-multiple-apache-tomcat-vulnerabilities

> CERT-FR reports multiple vulnerabilities in Apache Tomcat 9, 10.1, and 11.0 allowing denial of service, data integrity compromise, and security bypass; patches available.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Apache Tomcat affecting versions 9.0.x prior to 9.0.122, 10.1.x prior to 10.1.60, and 11.0.x prior to 11.0.26. The vulnerabilities collectively allow a remote attacker to cause denial of service, compromise data integrity, or bypass security policy mechanisms within affected Tomcat instances. Thirteen CVEs are referenced in the advisory, though the bulletin does not provide granular technical detail on each individual flaw's mechanism.

Apache has released fixed versions (9.0.122, 10.1.60, and 11.0.26) addressing these issues, with the vendor's own security bulletins dated 15 September 2026 providing the authoritative per-CVE breakdown. No evidence of active exploitation in the wild is mentioned in this advisory. Defenders running Apache Tomcat should prioritize identifying affected instances across their estate and apply the vendor-supplied patches according to their standard change management processes, referencing the Apache Tomcat security pages for version-specific details on each CVE.

## Mentioned in this report

- Vulnerabilities: CVE-2026-34500, CVE-2026-41293, CVE-2026-73581, CVE-2026-75973, CVE-2026-76183, CVE-2026-77756, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-86248, CVE-2026-86350, CVE-2026-87022

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1218

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/36825aa7-83ac-5886-81b6-256ed6feb71a/cert-fr-advisory-multiple-apache-tomcat-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
