Security Update Advisory for Apache Tomcat Vulnerabilities in August

Security Update Advisory for Apache Tomcat Vulnerabilities in August

Overview

Several vulnerabilities have been identified in Apache Tomcat, and a security update has been released. Affected users should update to Apache Tomcat version 10.1.59 Or later.

Affected Versions

  • Apache Tomcat versions 10.1.53 Through 10.1.57.
  • Apache Tomcat versions 10.1.24 Through 10.1.57.
  • Apache Tomcat versions 10.1.0-M1 through 10.1.57.
  • Systems that have removed the examples web application in accordance with security guidelines are not affected by CVE-2026-66299.

Resolved Vulnerabilities

  • Insufficient session expiration vulnerability (CVE-2026-73180, CVSS 6.8) Where a WebSocket session could persist even after an authenticated HTTP session has expired.
  • An authentication bypass vulnerability (CVE-2026-68569, CVSS 8.1) Where authentication may be granted if a user principal lookup fails under certain conditions.
  • A vulnerability that bypasses authentication in Apache Tomcat (CVE-2026-68525, CVSS 9.1).
  • A denial-of-service vulnerability caused by an unrestricted message buffer in a WebSocket chat example (CVE-2026-66299, CVSS 7.5).
  • A vulnerability that allows bypassing security constraints (CVE-2026-65182).
  • A vulnerability (CVE-2026-65183, CVSS 8.1) That allows an unauthorized local user to access a socket due to a TOCTOU race condition during the process of setting specific permissions for a Unix domain socket.
  • A denial-of-service vulnerability in Apache Tomcat (CVE-2026-68763, CVSS 7.5).
  • A vulnerability that allows bypassing declarative role constraints through Servlet role references (CVE-2026-66422, CVSS 8.1).
  • A vulnerability caused by an incomplete fix for CVE-2026-65183 (CVE-2026-65637, CVSS 9.8).
  • A vulnerability in RewriteValve where using the [N] flag causes processing to restart from the second rule, allowing access control to be bypassed (CVE-2026-65927, CVSS 7.5).
  • A vulnerability that bypasses authentication in Apache Tomcat (CVE-2026-65905, CVSS 9.8).

Recommended Actions

In accordance with the security advisory published on August 26, 2026, you must update to Apache Tomcat 10.1.59 Or later. For more details, refer to the Apache Tomcat security advisory.