The Apache Tomcat project has fixed 12 security flaws in its widely used Java web server, the most serious of which lets an attacker slip past the access rules that are supposed to protect WebSocket endpoints. The fixes ship in Tomcat 11.0.26, 10.1.60 and 9.0.122, and Apache's security pages made the issues public on September 23.
Hong Kong's HKCERT flagged the batch as Medium Risk on September 29, warning that a remote attacker could use some of the bugs for denial of service, security restriction bypass and data manipulation. Apache itself rates four of the twelve Important, three Moderate and five Low, and does not publish CVSS scores. None of them is reported as exploited.
A path parser that unlocked protected endpoints
CVE-2026-76183, rated Important, is the headline fix. Apache says request paths were incorrectly parsed as endpoint templates, which allowed the security constraints configured for WebSocket endpoints to be bypassed. In practice, an application that relied on Tomcat's constraints to decide who may open a WebSocket connection was not getting that protection. The NVD entry for this CVE lists a CVSS score of 9.8.
Three more flaws weaken authentication or certificate checks. CVE-2026-86248 (Moderate) means CLIENT_CERT authentication does not fail as expected in some scenarios when OCSP soft-fail is disabled; Apache calls it an incomplete fix for CVE-2026-34500, and its NVD entry also lists 9.8. CVE-2026-73581 (Moderate) found that the OpenSSL and OpenSSL-FFM TLS implementations ignored certificate revocation lists when the certificate used a keystore. CVE-2026-75973 (Low) caused an authentication mix-up across web applications when Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider.
HTTP/2, AJP and WebSocket take the other hits
- CVE-2026-86350 (Important): a regression in the fix for CVE-2026-41293 causes inconsistent interpretation of HTTP/2 requests and can mix up request headers. On the 11.x branch it affects only 11.0.22 to 11.0.25. NVD lists 9.1.
- CVE-2026-78383 (Important): a missing request body can pin an AJP processing thread, leading to denial of service.
- CVE-2026-77791 (Important): a busy wait while sending a WebSocket close message enables denial of service.
- CVE-2026-79677 (Moderate): a concurrency bug loses timeouts for asynchronous WebSocket writes, enabling denial of service.
- Low: WebSocket message smuggling with per-message-deflate (CVE-2026-87022), a malformed HTTP/2 request that can make another user's request fail (CVE-2026-78437), trailer fields injected into another HTTP/2 request by a stale HPACK emitter (CVE-2026-77762), and Transfer-Encoding honored on HTTP/1.0 requests behind a reverse proxy (CVE-2026-77756).
Upgrade to 11.0.26, 10.1.60 or 9.0.122
HKCERT lists the affected ranges as 9.0.0.M1 to 9.0.121, 10.1.0-M1 to 10.1.59 and 11.0.0-M1 to 11.0.25, though the exact range differs flaw by flaw. Administrators should move to the fixed release for their branch, using Apache's notes for Tomcat 9, Tomcat 10.1 and Tomcat 11. Servers that expose WebSocket endpoints, HTTP/2 or an AJP connector to untrusted networks have the most to gain, and teams that do not use AJP can close that path entirely by disabling the connector.
Tomcat bugs do get exploited: CISA added one to its Known Exploited Vulnerabilities catalog in August, as we reported at the time. Nothing in this batch has reached that stage, which makes this the cheapest moment to patch it.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.