← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 24, 2026 · 04:04via Cyber Security News

Apache Tomcat Update Fixes WebSocket and HTTP/2 Flaws Affecting Server Security

Brief

Apache Software Foundation has released Tomcat 11.

  • 26 to address 12 security vulnerabilities spanning WebSocket, HTTP/2 , AJP, authentication, and TLS certificate validation.

The flaws, disclosed September 23, 2026, include four rated Important, three Moderate, and five Low, giving administrators a broad but urgent patching task across internet-facing Java application servers.

Most existing Tomcat 11 deployments are exposed: many issues affect versions 11.

  • 0-M1 through 11.
  • 25, while narrower flaws begin at 11.
  • 0-M5, 11.
  • 0-M14, 11.
  • 19, or 11.
  • 22. Apache does not provide binary patches for individual vulnerabilities and advises users to install a release containing the fixes, making 11.
  • 26 the practical remediation baseline.
Read more on Cyber Security News→