Wednesday September 16, 2026

Advisory ID:   ngCERT-2026-080009

Damage:      Critical 

Probability:  High

Platform(s):  Apache Tomcat 9.x, 10.1.x and 11.x

SUMMARY

ngCERT is aware of multiple vulnerabilities in Apache Tomcat affecting security-constraint processing, authentication, URL rewriting, HTTP/2, WebSocket sessions, and Unix Domain Socket permissions. The flaws include security-control bypasses and denial-of-service conditions, with significant vulnerabilities enabling security-constraint bypass, Rewrite-Valve access-control bypass, authentication fail-open behaviour, and HTTP/2 resource exhaustion. Accordingly, ngCERT strongly recommends that organisations identify affected Tomcat installations, assess their configurations, and upgrade to the latest supported releases,
Tomcat 11.0.25, 10.1.59, or 9.0.121, as applicable.

DESCRIPTION

The vulnerabilities affect multiple Apache Tomcat security mechanisms, including security constraints, authentication, URL rewriting, role authorisation, HTTP/2, WebSocket sessions and Unix Domain Sockets. They may allow attackers to bypass access controls, circumvent HTTP-method restrictions, exploit authentication fail-open conditions, replay DIGEST-authenticated requests, or gain unauthorised access to protected resources. Key flaws include CVE-2026-65182 and CVE-2026-65927 affecting security constraints and RewriteValve rules; CVE-2026-68569CVE-2026-68525 and CVE-2026-66422 affecting authentication and authorisation; and CVE-2026-68763 and CVE-2026-65637 affecting HTTP/2 processing.

CVE-2026-65183 introduces a Unix Domain Socket race condition, while CVE-2026-73180 may allow authenticated WebSocket sessions to persist beyond their associated HTTP sessions. Apache has released fixes in Tomcat 11.0.25, 10.1.59 and 9.0.121. Organizations should review affected configurations, monitor for exploitation, and promptly upgrade vulnerable deployments to the appropriate fixed versions.

CONSEQUENCES

Successful exploitation of these vulnerabilities could lead to:

    1. Unauthorised Access
    2. Authentication Bypass
    3. Privilege Escalation
    4. Denial-of-Service
    5. Session Compromise
    6. Operational Disruption 

SOLUTION/MITIGATION

ngCERT strongly advises the following actions:

    1. Upgrade affected Apache Tomcat installations to 11.0.25, 10.1.59 or 9.0.121, as applicable.
    2. Inventory all Tomcat deployments and identify vulnerable instances.
    3. Review security, authentication, authorisation, and RewriteValve configurations.
    4. Restrict unnecessary exposure to HTTP/2 and monitor abnormal activity.
    5. Remove unused Tomcat components and example applications.
    6. Secure Unix Domain Sockets and enforce least-privilege access.
    7. Monitor for suspicious activity and migrate unsupported Tomcat versions.  

HYPERLINK