Security Update Advisory for Apache Tomcat Vulnerabilities in July

Security Update Advisory for Apache Tomcat Vulnerabilities in July

Apache Tomcat July Vulnerability Security Update Advisory


Apache Tomcat has released a security update to address vulnerabilities in the product. Users of this product should update to the latest version.

Affected Products


  • Apache Tomcat 9.0.13 – 9.0.119.
  • Apache Tomcat 9.0.0.M1 – 9.0.119.
  • Apache Tomcat 11.0.0-M1 – 11.0.23.
  • Apache Tomcat 10.1.0-M1 – 10.1.56.

Resolved Vulnerabilities


  • CVE-2026-59084. A vulnerability in Apache Tomcat titled EncryptInterceptor requirements not clearly documented, rated CVSS 9.1.
  • CVE-2026-59083. A vulnerability in Apache Tomcat titled Incorrect URL decoding in RewriteValve may allow security control bypass, rated CVSS 9.1.

Patch Information


In accordance with the security patch published on July 15, 2026, we have updated to the following versions:

  • Apache Tomcat 9.0.120.
  • Apache Tomcat 11.0.24.
  • Apache Tomcat 10.1.57.

References