Apache Tomcat fixes 12 flaws, led by a WebSocket bypass

Published

The Apache Tomcat project has fixed 12 security flaws in its widely used Java web server, the most serious of which lets an attacker slip past the access rules that are supposed to protect WebSocket endpoints. The fixes ship in Tomcat 11.0.26, 10.1.60 and 9.0.122, and Apache's security pages made the issues public on September 23.

Hong Kong's HKCERT flagged the batch as Medium Risk on September 29, warning that a remote attacker could use some of the bugs for denial of service, security restriction bypass and data manipulation. Apache itself rates four of the twelve Important, three Moderate and five Low, and does not publish CVSS scores. None of them is reported as exploited.

A path parser that unlocked protected endpoints

CVE-2026-76183, rated Important, is the headline fix. Apache says request paths were incorrectly parsed as endpoint templates, which allowed the security constraints configured for WebSocket endpoints to be bypassed. In practice, an application that relied on Tomcat's constraints to decide who may open a WebSocket connection was not getting that protection. The NVD entry for this CVE lists a CVSS score of 9.8.

Three more flaws weaken authentication or certificate checks. CVE-2026-86248 (Moderate) means CLIENT_CERT authentication does not fail as expected in some scenarios when OCSP soft-fail is disabled; Apache calls it an incomplete fix for CVE-2026-34500, and its NVD entry also lists 9.8. CVE-2026-73581 (Moderate) found that the OpenSSL and OpenSSL-FFM TLS implementations ignored certificate revocation lists when the certificate used a keystore. CVE-2026-75973 (Low) caused an authentication mix-up across web applications when Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider.

HTTP/2, AJP and WebSocket take the other hits

Upgrade to 11.0.26, 10.1.60 or 9.0.122

HKCERT lists the affected ranges as 9.0.0.M1 to 9.0.121, 10.1.0-M1 to 10.1.59 and 11.0.0-M1 to 11.0.25, though the exact range differs flaw by flaw. Administrators should move to the fixed release for their branch, using Apache's notes for Tomcat 9, Tomcat 10.1 and Tomcat 11. Servers that expose WebSocket endpoints, HTTP/2 or an AJP connector to untrusted networks have the most to gain, and teams that do not use AJP can close that path entirely by disabling the connector.

Tomcat bugs do get exploited: CISA added one to its Known Exploited Vulnerabilities catalog in August, as we reported at the time. Nothing in this batch has reached that stage, which makes this the cheapest moment to patch it.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions