Apache: 25 Vulnerabilities Disclosed, Critical Flaws Hit Tomcat on Sep 23-24, 2026
Key findings • 25 vulnerabilities disclosed across Apache projects, with a heavy focus on Apache Tomcat. • Critical flaws in Tomcat include authentication bypasses (CVE-2026-86248, CVE-2026-7…

Key findings
- 25 vulnerabilities disclosed across Apache projects, with a heavy focus on Apache Tomcat.
- Critical flaws in Tomcat include authentication bypasses (CVE-2026-86248, CVE-2026-76183) and HTTP/2 request smuggling (CVE-2026-86350).
- Multiple denial-of-service vulnerabilities affect Tomcat's WebSocket and AJP processing.
- Affected Tomcat versions range widely, with recommended upgrades including 11.0.26, 10.1.60, and 9.0.122.
- Other affected Apache projects include Airflow, DolphinScheduler, Doris, and Sling.
On September 23 and 24, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple Apache projects, with a strong focus on Apache Tomcat. These vulnerabilities span a range of severities, including critical flaws that could lead to authentication bypass, request smuggling, and denial-of-service conditions. The disclosures highlight potential risks for organizations relying on Apache's widely used software, particularly in web server and application hosting environments.
A substantial number of the disclosed vulnerabilities affect Apache Tomcat, with many impacting a broad range of versions. Several critical vulnerabilities, including CVE-2026-86248 and CVE-2026-76183, allow for authentication bypasses, potentially enabling unauthorized access to applications. Additionally, CVE-2026-86350, a critical HTTP/2 request smuggling vulnerability, could allow attackers to interfere with or impersonate other users' requests.
Multiple denial-of-service (DoS) vulnerabilities were also detailed. CVE-2026-87022, for instance, stems from improper handling of length parameters in WebSocket messages, while CVE-2026-78383 describes an unauthenticated AJP request that can pin a processing thread, leading to a DoS. Other DoS-related issues include CVE-2026-79677 (loss of timeouts for WebSocket writes) and CVE-2026-77791 (DoS during WebSocket close message sending).
Beyond critical and high-severity flaws, several medium and low-severity vulnerabilities were also part of this disclosure batch. CVE-2026-86246, a critical vulnerability in Apache Tomcat Native, enabled insecure default options. CVE-2026-86247, also in Tomcat Native, presented a race condition that could downgrade client certificate verification. Apache Doris users should be aware of CVE-2026-96443, a medium-severity RCE vulnerability due to insufficient validation of JDBC driver URLs. Apache Airflow users face CVE-2026-97636, where a team-scope guard in the HashiCorp Vault secrets backend can be bypassed. Apache DolphinScheduler users should note CVE-2026-57590, a high-severity missing authorization vulnerability in Task Group APIs.
The Apache Software Foundation has released updates to address these vulnerabilities. For Apache Tomcat, version 11.0.26, 10.1.60, and 9.0.122 are recommended as remediation baselines, as binary patches for individual vulnerabilities are not provided. Users of Apache Sling Security Bundle are advised to upgrade to version 1.3.12 or 1.3.2, and Apache Sling XSS users should upgrade to version 2.4.12. For Apache DolphinScheduler, version 3.4.3 is the recommended upgrade.
This extensive disclosure underscores the importance of timely patching and security updates for Apache products. The concentration of critical vulnerabilities in Apache Tomcat, particularly those related to authentication and HTTP/2, presents a significant risk to applications relying on this server. Organizations should prioritize updating their Apache Tomcat instances and other affected Apache software to the recommended versions to mitigate these security risks. The broad range of affected versions means that even older, yet still in-use, deployments may require attention.
The vulnerabilities detailed in this batch include: CVE-2026-97636, CVE-2026-57590, CVE-2026-86247, CVE-2026-86246, CVE-2026-86243, CVE-2026-87022, CVE-2026-86350, CVE-2026-86248, CVE-2026-79677, CVE-2026-78437, CVE-2026-78383, CVE-2026-77791, CVE-2026-77762, CVE-2026-77756, CVE-2026-76183, CVE-2026-75973, CVE-2026-73581, CVE-2026-96443, CVE-2026-94251, CVE-2026-94243, CVE-2026-92001, CVE-2026-91999, CVE-2026-91928, CVE-2026-91852, CVE-2026-73192.
Further context from related coverage indicates that the Apache Tomcat vulnerabilities, in particular, were disclosed on September 23, 2026, and include critical flaws such as HTTP/2 request smuggling and authentication bypasses. Recommended upgrades for Tomcat include versions 11.0.26, 10.1.60, and 9.0.122. Cyber Security News Vypr Intelligence