CVE-2026-24734General(apache / tomcat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat
  • tomcat_native

Threat summary

  • Patch or workaround signal is available
  • 19 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 8 classified signals
  • Disclosure: 7 classified signals
  • Peaked 5d ago at 7 mentions (2026-02-19); latest day: 1
  • 19 total mentions across 8 days

Affected systems

Vendors
Products
tomcattomcat_native

2 versions affected across 2 products

Deep dive

Activity timeline19 mentions / 8d
02457Mentions · 2026-02-17: 1Mentions · 2026-02-18: 3Mentions · 2026-02-19: 7Mentions · 2026-03-09: 3Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-03-23: 2Mentions · 2026-04-16: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-09: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-23: 2Technical Details · 2026-04-16: 102-1702-1802-1903-0903-1203-1603-2304-16
Signal classification3 categories
General
842.1%
Disclosure
736.8%
Patch
421.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-02-183
Disclosure1General2
2026-02-197
Disclosure4General2Patch1
2026-03-093
General1Patch2
2026-03-121
Patch1
2026-03-161
General1
2026-03-232
Disclosure1General1
2026-04-161
General1
Full discourse19 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Apache ❗ CVE-2026-24734 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-apache-7/ https://t.co/IThTJOLw9B

    Post summary

    Alert announcing the discovery of CVE‑2026‑24734 affecting Apache products, directing readers to external links for further information.

    03073550
    6.6K followersView on X
  • cPanel@cPanel
    General

    EasyApache 4 v25.48: • mod_qos → 11.78 • ionCube 15 added (beta for PHP 8.5) • ea-cpanel-tools manifest updated to include ioncube15 • Tomcat 10.1 changelog updated with CVE refs (CVE-2026-24733, CVE-2026-24734, CVE-2025-66614) Full change log: https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ https://t.co/a0lNz1sFp0

    Post summary

    The post announces an EasyApache 4 update that includes references to several CVEs in the Tomcat changelog, but it provides no technical details, PoC, exploit, or patch information.

    00130405
    28.7K followersView on X
  • Tomitribe@tomitribe
    General

    CVE-2026-24733 is an #ApacheTomcat vulnerability tied to HTTP/0.9, but its impact isn’t always clear. Join our team live to break down risk and exposure. Also covering: - CVE-2026-24734 - CVE-2025-66614 📅 Apr 22 at 10AM PT Save your spot: https://bit.ly/3Qep1KC https://t.co/iNsXqpP9JA

    Post summary

    An invitation to a live session discussing the potential risks of CVE-2026‑24733, CVE-2026‑24734, and CVE‑2025‑66614, highlighting their association with Apache Tomcat and HTTP/0.9.

    00011396
    3.1K followersView on X
  • 豊月@yutuki_r
    General

    Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #security #feedly

    Post summary

    The tweet notes several Apache Tomcat CVEs and links to a JVN article, but provides no further technical or exploit details.

    1100087
    1.0K followersView on X
  • transilienceai@transilienceai
    Patch

    @yutuki_r @okomeki - **For CVE-2026-24734**: Apache Tomcat Native 2.0.12 or 1.3.5; Apache Tomcat 11.0.18 or later, 10.1.52 or later, or 9.0.115 or later. #SecurityPatch

    Post summary

    The tweet supplies the specific Tomcat and Tomcat Native versions that need upgrading to mitigate CVE‑2026‑24734.

    1000039
    311 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @yutuki_r @okomeki - **CVE-2026-24734**: Apache Tomcat Native 2.0.11 and earlier, 1.3.4 and earlier; Apache Tomcat 11.0.0-M1 to 11.0.17, 10.1.0-M1 to 10.1.51, 9.0.0.M1 to 9.0.114. #ApacheTomcat

    Post summary

    The tweet announces CVE-2026-24734, listing the affected Apache Tomcat and Tomcat Native versions.

    1000037
    311 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @yutuki_r @okomeki 🚨 Apache Tomcat has multiple recently disclosed vulnerabilities: **CVE-2025-66614** (client certificate authentication bypass), **CVE-2026-24733** (security constraint bypass for GET requests), and **CVE-2026-24734** (certificate revocation check bypass). #ApacheTomcat #Security

    Post summary

    The tweet announces that Apache Tomcat has recently disclosed several CVEs affecting authentication and request handling mechanisms.

    1000045
    311 followersView on X
  • Kazuki Omo@omokazuki
    General

    Apache Tomcatの脆弱性(Moderate: CVE-2026-24734, Low: CVE-2026-24733) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260219/

    Post summary

    The post merely announces the existence of two Apache Tomcat CVEs (CVE-2026-24734 and CVE-2026-24733) with severity levels, providing no further exploitation, patch, or technical details.

    00010115
    360 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24734 OCSP Verification Bypass Vulnerability in Apache Tomcat Native and Tomcat https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24734

    Post summary

    A newly disclosed OCSP verification bypass vulnerability in Apache Tomcat Native and Tomcat has been identified, but no details on exploitation or mitigations are provided.

    0001048
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Nati… https://www.cve.org/CVERecord?id=CVE-2026-24734 ----- Traducción: CVE-2026-24734 Vul… http://infoflow.cloud`

    Post summary

    This post announces a new CVE (CVE‑2026‑24734) claiming an Improper Input Validation flaw in Apache Tomcat Native related to OCSP use, without providing exploit details, patches, or evidence of active exploitation.

    0000040
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Nati… https://www.cve.org/CVERecord?id=CVE-2026-24734

    Post summary

    The post references CVE‑2026‑24734 as an Improper Input Validation issue but provides no actionable details such as a PoC, exploit, patch, or evidence of active exploitation.

    00000207
    56.8K followersView on X
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. 💉 CVE-2026-2620 (CVSS: 7.3) 2. 🧱 CVE-2026-26736 (CVSS: 8.8) 3. 🧱 CVE-2026-26732 (CVSS: 8.8) 4. 🧱 CVE-2026-26731 (CVSS: 8.8) 5. ⚠️ CVE-2026-24734 (CVSS: 7.5) #CyberSecurity #CVE #Infosec

    Post summary

    The post merely lists recent CVEs with their CVSS scores, offering no further technical, exploit, or mitigation information.

    0000057
    169 followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases critical Tomcat 11.0.18 security update for SLES and openSUSE, fixing CVE-2025-66614, CVE-2026-24733 and CVE-2026-24734 affecting TLS cert checks and HTTP/0.9 handling. #Vulnerability https://threatcluster.io/cluster/suse-releases-critical-security-patch-for-tomcat-11-addressi-28d66904

    Post summary

    SUSE announced a critical security patch for Tomcat 11.0.18 that addresses CVE‑2025‑66614, CVE‑2026‑24733, and CVE‑2026‑24734, fixing issues with TLS certificate checks and HTTP/0.9 handling. No PoC, exploit, or active exploitation is reported.

    00000149
    100 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #openSUSE Tumbleweed ships Tomcat 9.0.115-1.1, addressing 3 CVEs (CVE-2025-66614, CVE-2026-24733, CVE-2026-24734). Read more: 👉 https://tinyurl.com/2rb5a6t3 #Security https://t.co/aJhl7pQJr3

    Post summary

    The tweet announces that openSUSE Tumbleweed has shipped a Tomcat update (9.0.115‑1.1) that includes patches for three identified CVEs.

    0000063
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #Tomcat 11 update for openSUSE Tumbleweed. Version 11.0.18-1.1 fixes CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734. Read more: 👉 https://tinyurl.com/pzdjwutx #openSUSE https://t.co/HxBRM65MmY

    Post summary

    The tweet announces an openSUSE Tomcat 11 update that includes a patch for three CVEs.

    0000065
    1.3K followersView on X
  • kawn@kawn2020
    Disclosure

    2026. 2.18 JVNVU#91658988 Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) - Japan Vulnerability Notes(JVN) https://jvn.jp/vu/JVNVU91658988/

    Post summary

    The JVN note references multiple Apache Tomcat CVEs but does not provide PoC, exploit, patch, or technical details.

    0000060
    89 followersView on X
  • jpsecuritynews@jpsecuritynews
    General

    [JVNVU#91658988] Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #jvn #脆弱性 #セキュリティ

    Post summary

    A brief tweet linking to a JVN report for multiple Apache Tomcat CVEs, providing no additional technical or exploit details.

    0000048
    30 followersView on X
  • 珈琲好き@likecoffee
    General

    Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #%E6%8A%80%E8%A1%93%E7%B3%BB-%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3 #feedly

    Post summary

    The tweet lists three Apache Tomcat CVEs with a link to a Japanese vulnerability database but offers no additional technical details or contextual information.

    0000048
    1.5K followersView on X
  • ITセキュリティ情報@itsec_jp
    Disclosure

    統合版 JPCERT/CC | JVN: Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://ift.tt/wUAnzvK #itsec_jp

    Post summary

    The post announces several CVE identifiers for Apache Tomcat and links to a JVN page, but provides no further technical details, exploit code, or patch information.

    00000100
    1.2K followersView on X
CPE platform detail48 entries

48 of 48 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat_native---

Explore more