Apache Tomcat Security Update Advisory

Apache Tomcat Security Update Advisory

Apache Tomcat Security Update Advisory


A security update addressing vulnerabilities in Apache Tomcat has been released. Users of this product should update to the latest version.

Affected Products

  • Apache Tomcat 11.0.0-M1 through 11.0.23.
  • Apache Tomcat 10.1.0-M1 through 10.1.56.
  • Apache Tomcat 9.0.0.M1 through 9.0.119.

Resolved Vulnerabilities

  • CVE-2026-59083: A security control bypass vulnerability in Apache Tomcat.
  • CVE-2026-59084. A vulnerability in Apache Tomcat’s EncryptInterceptor (a component related to encryption processing) due to insufficient technical documentation.

Patch Information

Vulnerability Patches are available in the latest updates. You must update to the following versions or higher:

  • Apache Tomcat 11.0.24 Or higher.
  • Apache Tomcat 10.1.57 Or higher.
  • Apache Tomcat 9.0.120 Or later.

Reference Sites

  • Apache Tomcat 9.X vulnerabilities.
  • Apache Tomcat 10.X vulnerabilities.
  • Apache Tomcat 11.X vulnerabilities.