Apache Tomcat Update Fixes WebSocket and HTTP/2 Flaws Affecting Server Security
Brief
Apache Software Foundation has released Tomcat 11.
- 26 to address 12 security vulnerabilities spanning WebSocket, HTTP/2 , AJP, authentication, and TLS certificate validation.
The flaws, disclosed September 23, 2026, include four rated Important, three Moderate, and five Low, giving administrators a broad but urgent patching task across internet-facing Java application servers.
Most existing Tomcat 11 deployments are exposed: many issues affect versions 11.
- 0-M1 through 11.
- 25, while narrower flaws begin at 11.
- 0-M5, 11.
- 0-M14, 11.
- 19, or 11.
- 22. Apache does not provide binary patches for individual vulnerabilities and advises users to install a release containing the fixes, making 11.
- 26 the practical remediation baseline.
