Apache Tomcat July Security Update Advisory
Apache Tomcat has released a security update that addresses vulnerabilities in the product. Users of the affected product are advised to update to the latest version.
Affected Products
- Apache Tomcat 9.0.13 – 9.0.119.
- Apache Tomcat 9.0.0.M1 – 9.0.119.
- Apache Tomcat 11.0.0-M1 – 11.0.23.
- Apache Tomcat 10.1.0-M1 – 10.1.56.
Resolved Vulnerabilities
- CVE-2026-59084. A vulnerability in Apache Tomcat,
EncryptInterceptor requirements not clearly documented, rated CVSS 9.1. - CVE-2026-59083. A vulnerability in Apache Tomcat,
Incorrect URL decoding in RewriteValve may allow security control bypass, rated CVSS 9.1.
Patch Information
In accordance with the security advisory published on July 15, 2026, the following versions have been released as updates.
- Apache Tomcat 9.0.120.
- Apache Tomcat 11.0.24.
- Apache Tomcat 10.1.57.
References
Related posts

The real problem is not the vulnerability — it is the 23%

The plugins you installed to stay safe are the ones opening the door — backup and anti-spam plugins hit in the same week (late July 2026)

Comments (0)
No comments yet. Be the first to comment.