# Apache Tomcat patches two security bypass flaws

Published: 2026-07-15 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/e216efc9-8009-576b-8a87-fb5c6cca46d7/apache-tomcat-patches-two-security-bypass-flaws

> Apache Tomcat fixed two vulnerabilities allowing security policy bypass across the 9.0, 10.1, and 11.0 branches.

ANSSI-FR issued an advisory covering multiple vulnerabilities in Apache Tomcat affecting versions 9.0.x prior to 9.0.120, 10.1.x prior to 10.1.57, and 11.0.x prior to 11.0.24. The flaws, tracked as CVE-2026-59083 and CVE-2026-59084, allow an attacker to cause a security policy bypass; the vendor has not specified further technical details of the underlying issue.

Apache released fixed versions on July 7-8, 2026, and administrators are advised to apply the patches referenced in the official Apache Tomcat security bulletins. No public exploitation has been reported at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59083, CVE-2026-59084

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0876

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e216efc9-8009-576b-8a87-fb5c6cca46d7/apache-tomcat-patches-two-security-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
