Apache Tomcat patches two security bypass flaws
Apache Tomcat fixed two vulnerabilities allowing security policy bypass across the 9.0, 10.1, and 11.0 branches.
ANSSI-FR issued an advisory covering multiple vulnerabilities in Apache Tomcat affecting versions 9.0.x prior to 9.0.120, 10.1.x prior to 10.1.57, and 11.0.x prior to 11.0.24. The flaws, tracked as CVE-2026-59083 and CVE-2026-59084, allow an attacker to cause a security policy bypass; the vendor has not specified further technical details of the underlying issue.
Apache released fixed versions on July 7-8, 2026, and administrators are advised to apply the patches referenced in the official Apache Tomcat security bulletins. No public exploitation has been reported at this time.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0876
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free