Multiple vulnerabilities in Apache Tomcat (August 26, 2026)
Multiple vulnerabilities have been discovered in Apache Tomcat. They allow an attacker to cause remote denial of service and security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities in Apache Tomcat enable remote denial of service and security policy bypass.
- Who is affected
- Apache Tomcat deployments.
- Urgency
- Moderate; denial of service and policy bypass issues present.
- Action
- Apply Apache Tomcat security updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tomcat
Get an email when a new Tomcat advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1083/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-329900.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-687630.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-685690.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-651830.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-685250.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-656370.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-651820.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-731800.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-664220.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-662990.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-32990 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-68763 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-68569 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65183 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-68525 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65637 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65182 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73180 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66422 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66299 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65905 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65927 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Apache Tomcat: Multiple Vulnerabilitiescert-bund
- mediumCVE-2026-73180: Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID fo…nvd
- highCVE-2026-68763: Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the…nvd
- highCVE-2026-68569: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. …nvd
- criticalCVE-2026-68525: Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows th…nvd
- highCVE-2026-66422: Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions b…nvd
- highCVE-2026-65927: Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves c…nvd
- criticalCVE-2026-65905: Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator.…nvd
- criticalCVE-2026-65637: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32…nvd
- highCVE-2026-65183: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating…nvd
- criticalCVE-2026-65182: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to secur…nvd
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
Recent advisories for Apache Tomcat
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Apache Tomcat: Multiple Vulnerabilitiescert-bund · 2026-08-26
- mediumCVE-2026-73180: Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID fo…nvd · 2026-08-25
- highCVE-2026-68763: Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the…nvd · 2026-08-25
- highCVE-2026-68569: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. …nvd · 2026-08-25
- criticalCVE-2026-68525: Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows th…nvd · 2026-08-25
- highCVE-2026-66422: Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions b…nvd · 2026-08-25
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Google Chrome (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in Veeam products (August 26, 2026)2026-08-26
- unknownVulnerability in Apereo CAS (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in SonicWall NetExtender (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in OpenSSL (August 26, 2026)2026-08-26