VORANT. Threat Intelligence Sign in Get the full feed

Apache Tomcat patches XSS and policy-bypass flaws

medium vulnerability

Apache patched multiple vulnerabilities in Tomcat 9.0.x, 10.1.x, and 11.0.x including XSS, security-policy bypass, and unspecified issues.

CERT-FR has issued an advisory for multiple vulnerabilities in Apache Tomcat affecting versions 9.0.x prior to 9.0.119, 10.1.x prior to 10.1.56, and 11.0.x prior to 11.0.23. The vulnerabilities enable remote cross-site scripting (XSS) attacks, security-policy bypass, and additional unspecified security issues.

Six CVEs have been assigned to the flaws: CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, CVE-2026-55955, and CVE-2026-55956. Apache released security bulletins on June 22-23, 2026, with patches available for all affected versions.

Organisations running vulnerable Tomcat versions should prioritise applying the available patches. Given Tomcat's widespread deployment as a Java servlet container in enterprise environments, timely remediation is important to prevent exploitation of the XSS and policy-bypass vulnerabilities.

Mentioned in this report

Vulnerabilities CVE-2026-50229templatedCVE-2026-53404CVE-2026-53434CVE-2026-55276CVE-2026-55955CVE-2026-55956

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0817

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free