Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-65637: Apache Tomcat can bypass certificate checks

CVE-2026-65637 · published 9 days ago
Summary

Certain 9.x, 10.x, and 11.x versions of Apache Tomcat have an incomplete fix that can let an attacker bypass the check that confirms the server is talking to the correct website. This could allow a malicious party to connect to the server pretending to be a trusted site. Upgrade Tomcat to the latest release (9.0.121, 10.1.58, or 11.0.25) to resolve the issue.

What to do
  • Update debian tomcat9 to version 9.0.70-2.
  • Update tomcat to version 11.0.25.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Debian:12 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Debian:13 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Debian:14 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Ubuntu:Pro:14.04:LTS canonical tomcat6 All versions
Ubuntu:Pro:14.04:LTS canonical tomcat7 All versions
Ubuntu:Pro:16.04:LTS canonical tomcat8 All versions
Ubuntu:Pro:18.04:LTS canonical tomcat9 All versions
Ubuntu:24.04:LTS canonical tomcat10 All versions
Ubuntu:26.04:LTS canonical tomcat11 All versions
apache software foundation apache tomcat <= 11.0.24
Debian:12 debian tomcat10 All versions
Debian:13 debian tomcat10 All versions
Debian:14 debian tomcat10 All versions
Debian:13 debian tomcat11 All versions
Debian:14 debian tomcat11 All versions
apache tomcat >= 9.0.115, < 9.0.121
>= 10.1.53, < 10.1.58
>= 11.0.20, < 11.0.25
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Bitnami tomcat >= 11.0.20, < 11.0.25
Fix: upgrade to 11.0.25
Original advisory text
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from...
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published25 Aug 2026
Updated3 Sep 2026
First seen25 Aug 2026
Monitor software like this
Free during beta