CVE-2026-55276Patch(apache / tomcat)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch apache tomcat systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-02: 2Active Exploitation · 2026-07-02: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-02: 106-3007-02
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
Active Exploitation
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure1Patch1
2026-07-022
Active Exploitation1Patch1
Full discourse4 posts
  • Kazuki Omo@omokazuki
    Disclosure

    Apache Tomcatの脆弱性(Important: CVE-2026-55957, Moderate: CVE-2026-55956, Low: CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE-2026-53404, CVE-2026-50229) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260630/

    Post summary

    The post announces several Apache Tomcat CVEs, indicating their severity, and links to a vulnerability article for further details.

    00010149
    369 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-55276 (CVSS 9.1) - Apache Tomcat control flow flaw exposes authorization constraints. Affects versions 8.5.0-11.0.22. Patch immediately to 11.0.23, 10.1.56, or 9.0.119. #CVE #PatchNow #ThreatIntel https://t.co/yyoxm474TM

    Post summary

    The tweet announces a critical Apache Tomcat vulnerability (CVE‑2026‑55276) and urges immediate patching to the specified newer versions.

    0000053
    56 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Apache Tomcat (CVE-2026-55276) https://vuldb.com/vuln/374706/cti

    Post summary

    CTI indicates that offensive activities targeting Apache Tomcat CVE-2026-55276 have been identified, implying active exploitation.

    00000133
    2.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Misleading Authorization Logging in Apache Tomcat (CVE-2026-55276) Apache Tomcat has an always-incorrect control flow bug that omits special roles and empty authorization constraints when it logs the effective web.xml, impacting the container’s security configuration reporting. The root cause is an incorrect control flow implementation leading to faulty logic during effective descriptor logging. An attacker can exploit this indirectly by relying on defenders and auditors to trust the logged effective web.xml output (no special privileges required beyond having a target where teams use these logs for validation), masking risky or unintended authorization behavior. The impact is inaccurate security-related logging that can mislead investigations and compliance checks, potentially allowing misconfigurations or unauthorized access paths to persist undetected. 👉 Affected: Apache Tomcat (prior to 11.0.23 / 10.1.56 / 9.0.119) | Upgrade to 11.0.23, 10.1.56, or 9.0.119

    Post summary

    The post announces a critical logging flaw in Apache Tomcat, details its technical impact, and provides specific upgrade paths to mitigate the risk.

    0000084
    232 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more