Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-65637: Apache Tomcat can bypass certificate checks
CVE-2026-65637 · published 9 days ago
Summary
Certain 9.x, 10.x, and 11.x versions of Apache Tomcat have an incomplete fix that can let an attacker bypass the check that confirms the server is talking to the correct website. This could allow a malicious party to connect to the server pretending to be a trusted site. Upgrade Tomcat to the latest release (9.0.121, 10.1.58, or 11.0.25) to resolve the issue.
What to do
- Update debian tomcat9 to version 9.0.70-2.
- Update tomcat to version 11.0.25.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Debian:12 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Debian:13 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Debian:14 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Ubuntu:Pro:14.04:LTS | canonical | tomcat6 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | tomcat7 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | tomcat8 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | tomcat9 | All versions |
| Ubuntu:24.04:LTS | canonical | tomcat10 | All versions |
| Ubuntu:26.04:LTS | canonical | tomcat11 | All versions |
| – | apache software foundation | apache tomcat | <= 11.0.24 |
| Debian:12 | debian | tomcat10 | All versions |
| Debian:13 | debian | tomcat10 | All versions |
| Debian:14 | debian | tomcat10 | All versions |
| Debian:13 | debian | tomcat11 | All versions |
| Debian:14 | debian | tomcat11 | All versions |
| – | apache | tomcat |
>= 9.0.115, < 9.0.121 >= 10.1.53, < 10.1.58 >= 11.0.20, < 11.0.25 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| Bitnami | – | tomcat |
>= 11.0.20, < 11.0.25 Fix: upgrade to 11.0.25
|
Original advisory text
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from...
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
References
- https://ubuntu.com/security/CVE-2026-65637 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-65637 Third Party Advisory
- https://github.com/apache/tomcat/commit/8639b20f045c88f356b887204f52e897399f0de7 Third Party Advisory
- https://github.com/apache/tomcat/commit/40012414df828a56126f76a7339669c7c919aae7 Third Party Advisory
- https://github.com/apache/tomcat/commit/b823e88da077f5fa973e34d72359bded9f621e3c Third Party Advisory
- https://lists.apache.org/thread/djog953z1ohsyt25bdvhfzbmsy22vgcj
- https://security-tracker.debian.org/tracker/CVE-2026-65637 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-65637 URL
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published25 Aug 2026
Updated3 Sep 2026
First seen25 Aug 2026
Sources
DEBIAN-CVE-2026-65637 · OSV
CVE-2026-65637 · NVD
CVE-2026-65637 · MITRE
BIT-tomcat-2026-65637 · OSV
UBUNTU-CVE-2026-65637 · OSV
Monitor software like this
Free during beta