CVE-2026-41293Disclosure(apache / tomcat)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache tomcat systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-05-12); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Mentions · 2026-06-10: 1Mentions · 2026-07-03: 1Mentions · 2026-09-23: 1Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-09-25: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-10: 1Technical Details · 2026-09-23: 1Technical Details · 2026-09-25: 105-1205-1406-1007-0309-2309-25
Signal classification3 categories
Disclosure
350.0%
General
233.3%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-141
Disclosure1
2026-06-101
Disclosure1
2026-07-031
General1
2026-09-231
Disclosure1
2026-09-251
PoC1
Full discourse6 posts
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Apache Tomcat'te CVSS 9.1 Critical HTTP/2 Request Smuggling açığı için @abraxas_null tarafından PoC yayınlandı. CVE-2026-86350, CVE-2026-41293 için yapılan düzeltmedeki regression nedeniyle HTTP/2 HPACK decoder state'inin bozulmasına ve aynı bağlantıdaki sonraki request'lerin header'larının yanlış yorumlanmasına yol açabiliyor. Unauthenticated / Remote — CWE-444 — CVSS 9.1 Etkilenen sürümler: 9.0.118–9.0.121, 10.1.55–59, 11.0.22–25 Düzeltilenler: 9.0.122 / 10.1.60 / 11.0.26 Yayınlanan PoC RCE değil; HTTP/2 header mix-up / request-smuggling koşulunu doğrulayan bir lab PoC'si. https://github.com/abraxas/CVE-2026-86350

    Post summary

    The tweet announces the release of a proof-of-concept for a critical Apache Tomcat HTTP/2 request smuggling vulnerability, providing technical details and patched versions while clarifying the PoC is not an RCE exploit.

    09037291.8K
    2.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 New Apache Tomcat flaws uncovered - and some could impact authentication & request handling. ⚠️ CVE-2026-43515 – Authorization bypass ⚠️ CVE-2026-41293 – HTTP/2 input validation issue ⚠️ CVE-2026-43512 – Digest authentication bypass If Tomcat is internet-facing, now is a good time to review exposure and patch ASAP. Attackers move fast once details go public. #CyberSecurity #AppSec #ApacheTomcat #CVE

    Post summary

    The post announces new Apache Tomcat CVEs that may affect authentication and HTTP/2 handling, urges quick patching, but offers no PoC or exploit details.

    00020114
    187 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-86350 Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can… https://www.cve.org/CVERecord?id=CVE-2026-86350

    Post summary

    The text is a brief disclosure of CVE-2026-86350, an HTTP request smuggling regression in Apache Tomcat, linking to the CVE record without mentioning exploits, PoCs, patches, or active exploitation.

    100001.7K
    58.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Atlassian ❗ CVE-2026-43515 ❗ CVE-2026-43512 ❗ CVE-2026-41293 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-atlassian-4/ https://t.co/g823YVvIKX

    Post summary

    The tweet merely lists three Atlassian product CVEs and points to a link for further information, without providing specifics about exploits, patches, or technical details.

    00010249
    6.7K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Ubuntu reported that Apache Tomcat before 9.0.118 is affected by CVE-2026-41284 and CVE-2026-41293, enabling remote attackers to exhaust memory with WebDAV requests and crash or take over servers via crafted HTTP/2 headers. https://threatcluster.io/cluster/multiple-vulnerabilities-discovered-in-tomcat-affecting-webd-380958fe

    Post summary

    Ubuntu reported two CVEs (CVE‑2026‑41284 and CVE‑2026‑41293) affecting Apache Tomcat versions prior to 9.0.118, enabling remote attackers to exhaust memory with WebDAV requests or crash/take over servers via crafted HTTP/2 headers. No PoC, exploit code, or active exploitation evidence is mentioned.

    0000050
    318 followersView on X
  • Kazuki Omo@omokazuki
    General

    Apache Tomcatの脆弱性(Moderate: CVE-2026-43512, CVE-2026-43515, Low: CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43513, CVE-2026-43514) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260513/

    Post summary

    The post enumerates a set of CVE identifiers for Apache Tomcat with severity tags but provides no technical detail, patches, or exploitation information.

    00000222
    371 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more