Security Update Advisory for Apache Tomcat Vulnerabilities in July
Apache Tomcat July Vulnerability Security Update Advisory
Apache Tomcat has released a security update to address vulnerabilities in the product. Users of this product should update to the latest version.
Affected Products
- Apache Tomcat 9.0.13 – 9.0.119.
- Apache Tomcat 9.0.0.M1 – 9.0.119.
- Apache Tomcat 11.0.0-M1 – 11.0.23.
- Apache Tomcat 10.1.0-M1 – 10.1.56.
Resolved Vulnerabilities
- CVE-2026-59084. A vulnerability in Apache Tomcat titled
EncryptInterceptor requirements not clearly documented, rated CVSS 9.1. - CVE-2026-59083. A vulnerability in Apache Tomcat titled
Incorrect URL decoding in RewriteValve may allow security control bypass, rated CVSS 9.1.
Patch Information
In accordance with the security patch published on July 15, 2026, we have updated to the following versions:
- Apache Tomcat 9.0.120.
- Apache Tomcat 11.0.24.
- Apache Tomcat 10.1.57.
References
- [1] http://cve.Mitre.Org/cgi-bin/cvename.Cgi?Name=CVE-2026-59084.
- [2] Http://cve.Mitre.Org/cgi-bin/cvename.Cgi?Name=CVE-2026-59083.
- [3] Https://tomcat.Apache.Org/security.