CVE-2026-43512Disclosure(apache / tomcat)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache tomcat systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-592

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-14); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-05-12: 1Mentions · 2026-05-14: 2Mentions · 2026-05-22: 1Mentions · 2026-06-09: 1Mentions · 2026-07-03: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-06-09: 1Exploit Tool / Code · 2026-06-09: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-09: 1Technical Details · 2026-09-24: 105-1205-1405-2206-0907-0309-24
Signal classification4 categories
Disclosure
342.9%
General
228.6%
Active Exploitation
114.3%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-142
Active Exploitation1Disclosure1
2026-05-221
General1
2026-06-091
PoC1
2026-07-031
Disclosure1
2026-09-241
Disclosure1
Full discourse7 posts
  • dbugs@ptdbugs
    PoC

    Apache Tomcat: Digest authenticator will authenticate any unknown user CVE: CVE-2026-43512 PT ID: PT-2026-40071 Vendor: Apache Software Foundation Product: Apache Tomcat CVSS: 9.8 Credits: n/a Description: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions may also be affected. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-43512 • https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73 PoC/Exploit: https://github.com/covepseng/cve-2026-43512-poc #dbugs_vuln

    Post summary

    Apache Tomcat digest authenticator flaw permits any unknown user to authenticate; a PoC exploit is available on GitHub, but no active exploitation is reported. The vulnerability has a CVSS score of 9.8.

    010671.5K
    2.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 New Apache Tomcat flaws uncovered - and some could impact authentication & request handling. ⚠️ CVE-2026-43515 – Authorization bypass ⚠️ CVE-2026-41293 – HTTP/2 input validation issue ⚠️ CVE-2026-43512 – Digest authentication bypass If Tomcat is internet-facing, now is a good time to review exposure and patch ASAP. Attackers move fast once details go public. #CyberSecurity #AppSec #ApacheTomcat #CVE

    Post summary

    The tweet announces newly discovered Apache Tomcat vulnerabilities and urges rapid patching, focusing on potential authentication and request handling impacts.

    00020114
    187 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Atlassian ❗ CVE-2026-43515 ❗ CVE-2026-43512 ❗ CVE-2026-41293 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-atlassian-4/ https://t.co/g823YVvIKX

    Post summary

    The tweet announces new CVE vulnerabilities affecting Atlassian products, providing links for further information but lacking technical, exploit, or remediation details.

    00010249
    6.7K followersView on X
  • Nishanth@Nishanth_KJ
    Disclosure

    Reviewing Tomcat auth flows? Look for CVE-2026-43512 in tomcat-coyote. Digest authentication bypass requires immediate dependency updates. #CVE #Tomcat #coyote

    Post summary

    The tweet announces CVE-2026-43512 in Apache Tomcat's tomcat-coyote component, describing it as a digest authentication bypass and highlighting the need for immediate dependency updates.

    0000029
    64 followersView on X
  • HeroDevs@herodevs
    General

    Apache's Tomcat 8.5 security page is the tip of the iceberg. 🧊 May 10, 2026: Apache shipped patches for seven new CVEs in 9.x, 10.1.x, and 11.x. Tomcat 8.5 isn't listed in any of them — but NVD confirms 8.5 is affected by every one. The standout: CVE-2026-43512. Any user not in the configured realm authenticates successfully if the request presents the literal password "null." Tomcat 8.5 reached EOL March 31, 2024. The CVE disclosures haven't stopped. The documentation just has. "No entry on Apache's page" ≠ "Not affected." It means the project stopped tracking your version. #ApacheTomcat #Tomcat #Java #EndOfLife #EOL #CVE #DevSecOps #VulnerabilityManagement #HeroDevs #NeverEndingSupport

    Post summary

    Apache Tomcat 8.5 is affected by CVE‑2026‑43512, resulting in an authentication bypass; no PoC, exploit, or patch is provided, and there's no evidence of active exploitation.

    00000148
    2.7K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Apache Tomcat (CVE-2026-43512) https://vuldb.com/vuln/363069/cti

    Post summary

    Actors are increasingly targeting Apache Tomcat CVE-2026-43512, indicating possible in-the-wild exploitation activity, although no exploit code or mitigation information is provided.

    0000073
    2.2K followersView on X
  • Kazuki Omo@omokazuki
    General

    Apache Tomcatの脆弱性(Moderate: CVE-2026-43512, CVE-2026-43515, Low: CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43513, CVE-2026-43514) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260513/

    Post summary

    A brief post lists several Tomcat CVEs with their severity levels and links to a source, but no additional technical, exploit or patch details are provided.

    00000222
    371 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more