Apache Tomcat patches XSS and policy-bypass flaws
Apache patched multiple vulnerabilities in Tomcat 9.0.x, 10.1.x, and 11.0.x including XSS, security-policy bypass, and unspecified issues.
CERT-FR has issued an advisory for multiple vulnerabilities in Apache Tomcat affecting versions 9.0.x prior to 9.0.119, 10.1.x prior to 10.1.56, and 11.0.x prior to 11.0.23. The vulnerabilities enable remote cross-site scripting (XSS) attacks, security-policy bypass, and additional unspecified security issues.
Six CVEs have been assigned to the flaws: CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, CVE-2026-55955, and CVE-2026-55956. Apache released security bulletins on June 22-23, 2026, with patches available for all affected versions.
Organisations running vulnerable Tomcat versions should prioritise applying the available patches. Given Tomcat's widespread deployment as a Java servlet container in enterprise environments, timely remediation is important to prevent exploitation of the XSS and policy-bypass vulnerabilities.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0817
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free