# Apache Tomcat patches XSS and policy-bypass flaws

Published: 2026-06-30 · Severity: medium
Canonical: https://vorant.io/reports/b572efa9-74ef-5ed4-86d2-d4f380c0977a/apache-tomcat-patches-xss-and-policy-bypass-flaws

> Apache patched multiple vulnerabilities in Tomcat 9.0.x, 10.1.x, and 11.0.x including XSS, security-policy bypass, and unspecified issues.

CERT-FR has issued an advisory for multiple vulnerabilities in Apache Tomcat affecting versions 9.0.x prior to 9.0.119, 10.1.x prior to 10.1.56, and 11.0.x prior to 11.0.23. The vulnerabilities enable remote cross-site scripting (XSS) attacks, security-policy bypass, and additional unspecified security issues.

Six CVEs have been assigned to the flaws: CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, CVE-2026-55955, and CVE-2026-55956. Apache released security bulletins on June 22-23, 2026, with patches available for all affected versions.

Organisations running vulnerable Tomcat versions should prioritise applying the available patches. Given Tomcat's widespread deployment as a Java servlet container in enterprise environments, timely remediation is important to prevent exploitation of the XSS and policy-bypass vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2026-50229 (templated), CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, CVE-2026-55955, CVE-2026-55956

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0817

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b572efa9-74ef-5ed4-86d2-d4f380c0977a/apache-tomcat-patches-xss-and-policy-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
