CVE-2026-55957Patch(apache / tomcat)

HIGHCVSS 7.3 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch apache tomcat systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-304

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 9 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 7 mentions (2026-07-01); latest day: 1
  • 14 total mentions across 7 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline14 mentions / 7d
02457Mentions · 2026-06-30: 2Mentions · 2026-07-01: 7Mentions · 2026-07-02: 1Mentions · 2026-07-04: 1Mentions · 2026-07-05: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-07-04: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-04: 1Patch / Workaround · 2026-07-01: 5Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-01: 5Technical Details · 2026-07-02: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-08: 106-3007-0107-0207-0407-0507-0807-09
Signal classification5 categories
Patch
750.0%
General
321.4%
Disclosure
214.3%
Active Exploitation
17.1%
Exploit
17.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-06-302
Active Exploitation1General1
2026-07-017
Disclosure1General1Patch5
2026-07-021
Patch1
2026-07-041
Exploit1
2026-07-051
Disclosure1
2026-07-081
Patch1
2026-07-091
General1
Full discourse14 posts
  • elhacker.NET@elhackernet
    Disclosure

    Múltiples vulnerabilidades de Apache Tomcat permiten saltar la autenticación La Apache Software Foundation ha revelado dos vulnerabilidades en Apache Tomcat (CVE-2026-55957 y CVE-2026-55956) https://blog.elhacker.net/2026/07/multiples-vulnerabilidades-de-apache.html

    Post summary

    The article announces that Apache Tomcat has two newly disclosed authentication bypass vulnerabilities (CVE‑2026‑55957 and CVE‑2026‑55956).

    011039103.8K
    141.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Apache Tomcatに認証回避の脆弱性。CVE-2026-55957はJNDIRealmがGSSAPI認証バインドにおける必須ステップをスキップすることにより、正規認証情報無しでの認証が可能となるもの。その他脆弱性複数と併せ修正。 https://securityonline.info/apache-tomcat-vulnerabilities-cve-2026-55957/

    Post summary

    A new authentication‑bypass flaw in Apache Tomcat’s JNDIRealm was disclosed, allowing credential‑less access; the issue has been patched alongside several other vulnerabilities.

    01050915
    7.7K followersView on X
  • Tre B@trerbbb
    General

    apache CVE-2026-55957. cloud misconfigs scale your blast radius by every region you operate in. audit IAM first. #Apache #CVE-2026-55957 https://valtikstudios.com/blog/apache-http2-cve-2026-23918-double-free-rce-may-2026

    Post summary

    The text references CVE-2026-55957 but lacks technical details, proofs of exploitation, or mitigation information, resulting in a general classification.

    0101045
    17 followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Seven Apache Tomcat vulnerabilities are patched, including an authentication bypass (CVE-2026-55957). Update to a fixed Tomcat release now. #ApacheTomcat #Tomcat #CVE202655957 #AuthenticationBypass #JNDIRealm #WebServerSecurity #Vulnerability https://securityonline.info/apache-tomcat-vulnerabilities-cve-2026-55957 https://t.co/TF11wBWHrm

    Post summary

    The tweet announces that seven Apache Tomcat vulnerabilities, including CVE-2026-55957, have been patched and urges users to update to a fixed release.

    01010431
    12.4K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Apache Tomcat (CVE-2026-55957) https://vuldb.com/vuln/374708/cti

    Post summary

    The post alerts to increased detection of activity against Apache Tomcat CVE-2026-55957, implying potential ongoing exploitation in the wild.

    00011142
    2.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache Tomcat の脆弱性 CVE-2026-55957/55956 が FIX:認証バイパスの恐れ https://iototsecnews.jp/2026/07/01/multiple-apache-tomcat-vulnerabilities-allow-attackers-to-bypass-authentication/ Webアプリケーションの安全な運用を支える基盤ソフト Apache Tomcat において、本来制限されているはずの領域へ向けた外部からの侵入を許してしまう、2 件の脆弱性CVE-2026-55957/CVE-2026-55956 が公表されました。この問題の背景には、通信の種類ごとにアクセスの可否を細かく判定する内部ロジックの不備により、設定された拒否ルールが一部無視されてしまう仕組み上の不具合があります。この脆弱性を放置すると、認証の回避や重要データの窃取などが生じる恐れがあります。対応策として、開発元が配布している安全な最新バージョンへの更新を速やかに実施してください。その上で、設定ファイルのアクセス制御ルールを改めて見直すことが大切です。 #Apache #CVE202655956 #CVE202655957 #Tomcat #Vulnerability

    Post summary

    The article announces two CVEs in Apache Tomcat that allow authentication bypass and recommends applying vendor patches and reviewing access‑control settings.

    01000157
    500 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    Tomcat の CVE で一番気になったのは、認証バイパスそのものより「まだそこに Tomcat 8.5 / 7.0 がいる」という現実だった。 CVE-2026-55957 は、JNDIRealm + GSSAPI authenticated bind という条件が必要で、発動条件は狭い。Tomcat を使っているだけで全員が慌てる話ではない。まず見るべきは、該当構成があるかどうか。 ただし、同時公開の CVE-2026-55956 は別。default servlet の制約バイパスで、影響範囲はこちらの方が広い。GSSAPI とは関係ないので、日本の現場で普通に踏む可能性があるのは、むしろこっちかもしれない。 見る順番はこう。 まず、JNDIRealm + GSSAPI の旧構成が残っていないか。単体 Tomcat だけでなく、Spring Boot 組み込みの tomcat-embed-core も見る。 次に、CVE-2026-55956 の影響範囲を確認する。 そしてログを見るなら、単なるログイン成功ではなく、 いつ どこから どの認証方式で どのロールになり その後何をしたか を見る。 いったん認証が通ってしまえば、その後は「正規の管理者操作」に見える。ここが厄介。 で、ここからが本題。 Tomcat 9 / 10 / 11 系なら、基本は修正版へ上げる話になる。でも 8.5 / 7.0 は EOL。該当した場合、「パッチを当てれば済む」ではなく、実質的には移行案件になる。 ここで現場は止まる。 古いから上げろ。 それは正しい。 でも正しいだけでは動かない。 その上に10年前の業務アプリが載っている。担当者はいない。検証環境もない。JDK を上げると別のものが壊れる。認証連携も古い。移行はセキュリティ対応ではなく、小さな再開発案件になる。 だから残る。 そして、残ったものが次の攻撃面になる。 ここで Aikido が買収した Root の意味が出てくる。 Root / Aikido Libraries / Aikido Images が狙っているのは、「見つける」と「直す」の間に空いた溝だ。 脆弱性を見つける側は、SCA、SAST、SBOM、AIでどんどん速くなった。でも直す側は、まだ人間の手作業に残っている。 影響を調べる。 上げられるバージョンを探す。 互換性を見る。 壊れないか試す。 本番反映を調整する。 攻撃者は、この「見つかったが、まだ直っていない」時間に住んでいる。 Root の発想は、いま動いているまさにそのバージョンに、破壊的変更を避けた修正を差し込むこと。アップグレードでも移行でもなく、壊れにくい差し替えに近い。 もちろん、これは EOL を放置していいという話ではない。古いものは、上げられるなら上げるべき。 ただ、日本企業の基幹周辺には「古いが止められない」「上げたいが検証環境がない」「担当者がもういない」システムが普通にある。 EOL の本当の怖さは、脆弱性そのものより、修正判断が毎回プロジェクト化して止まることにある。 今回の Tomcat CVE は、現時点で悪用が広がっている話ではない。CVE-2026-55957 の条件も狭い。過度に煽る必要はない。 でも、放置してよい話でもない。 該当構成を切り分ける。 CVE-2026-55956 も見る。 ブラウザ経路や管理画面との複合技を考える。 ログで認証方式・権限・操作を見る。 そして EOL が残っているなら、移行だけでなく、壊さず塞ぐ現実解も考える。 古い Tomcat が動いていた。 それは一台の古いサーバの話ではない。 「見つける」ことは速くなったのに、「直す」ことだけが遅いまま残っている。 今回の CVE は、その溝をもう一度見せている。 #Aikido #Tomcat #脆弱性管理 #サプライチェーンセキュリティ #DevSecOps #OSS

    Post summary

    The post discloses technical details of two Tomcat CVEs, highlights their narrow exploitable conditions, and advises migration or upgrading but does not provide PoC, exploit code, or evidence of active exploitation.

    00001353
    210 followersView on X
  • AlexAImaginator@TraffAlex
    Exploit

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 04, 2026 1️⃣ "BAD EPOLL" LINUX KERNEL VULNERABILITY HITS 6.4+ AND ANDROID WITH 99% RELIABILITY A critical race condition flaw named "Bad Epoll" (CVE-2026-46242) has been discovered in Linux kernel versions 6.4 and above, affecting a wide range of modern Linux distributions and newer Android devices. The vulnerability allows any unprivileged local user to escalate to full root access. The proof-of-concept achieves a remarkable 99% success rate and can potentially be triggered from Chrome's renderer sandbox, making exploitation from a compromised web page feasible. Security teams should audit kernel versions and apply available patches immediately. 🔹 @TheHackersNews 2️⃣ BAD EPOLL: THE KERNEL BUG MISSED BY MYTHOS — REAL-WORLD EXPLOIT DEMONSTRATED Security researcher Jaeyoung Chung detailed his exploitation of CVE-2026-46242, using the race condition in the eventpoll subsystem to claim a kernelCTF challenge. The vulnerability is not just theoretical — it also affects production Android kernels, meaning the attack surface extends far beyond desktop Linux systems. The exploit's high reliability underscores the seriousness of eventpoll race conditions in modern kernel implementations. 🔹 @linkersec 3️⃣ CISA ADDS MICROSOFT SHAREPOINT RCE TO KNOWN EXPLOITED VULNERABILITIES CATALOG CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, flagging an active remote code execution vulnerability in Microsoft SharePoint Server. The flaw stems from unsafe deserialization of untrusted data, allowing attackers to execute arbitrary code on on-premises SharePoint installations. Active exploitation has been confirmed in the wild, making immediate patching essential for any organization running SharePoint Server. 🔹 @CISACyber 4️⃣ CISA ISSUES THREE NEW AND THREE UPDATED ICS SECURITY ADVISORIES The Cybersecurity and Infrastructure Security Agency released three new public ICS (Industrial Control Systems) advisories alongside three updated ones. These advisories cover current security issues, vulnerabilities, and active exploits targeting industrial control systems — infrastructure that powers everything from energy grids to manufacturing facilities. Organizations operating ICS environments should review the full advisories on CISA's portal and assess their exposure. 🔹 @CISACyber 5️⃣ PEAR RANSOMWARE GROUP TARGETS SG'S CNW ELECTRONICS AND US BEVERAGE COMPANY The PEAR ransomware operation has added two new victims to its dark web data leak portal: CNW Electronics based in Singapore, a critical electronics sector company, and AC Beverage, Inc. in the United States. Reports indicate that approximately 4.6 terabytes of data were stolen from CNW Electronics alone. The group continues to demonstrate a pattern of targeting companies in critical infrastructure and supply chain sectors. 🔹 @FalconFeedsio 6️⃣ APACHE TOMCAT AUTHENTICATION BYPASS VULNERABILITY AFFECTS VERSIONS 7 THROUGH 11 CVE-2026-55957 is an authentication bypass vulnerability in Apache Tomcat that allows password-free login when GSSAPI-based authentication is configured. The flaw impacts a broad range of Tomcat versions spanning from 7 through 11, affecting installations that rely on GSSAPI for authentication. While active exploitation has not yet been confirmed, the wide version coverage makes this a priority for administrators running GSSAPI-configured Tomcat servers. 🔹 @MalwareBibleJP 7️⃣ BLOODHOUND ENTERPRISE HYGIENE FINDINGS: BEYOND ATTACK PATHS SpecterOps highlighted a powerful feature of BloodHound Enterprise — the Hygiene findings module. Unlike traditional attack path analysis that shows how adversaries reach their objective, Hygiene findings surface the underlying conditions attackers exploit: oversized default groups with delegated privileges, AS-REP roastable accounts, and Kerberoastable accounts. These hygiene issues may not be direct attack paths, but eliminating them removes the foundation that makes lateral movement and privilege escalation possible. 🔹 @SpecterOps 💭 The cybersecurity landscape this week is dominated by kernel-level threats and supply chain risks. The Bad Epoll vulnerability demonstrates how even fundamental OS primitives can harbor devastating race conditions, while CISA's KEV additions and ICS advisories remind us that critical infrastructure remains a top target. The common thread across all these stories is the need for proactive hygiene — patching, monitoring, and understanding the conditions that turn theoretical vulnerabilities into active exploits. Which of these vulnerabilities keeps you up at night — kernel exploits, ransomware campaigns, or ICS threats? Let me know below 👇 #Cybersecurity #CVE #LinuxKernel #Ransomware #CISA #InfoSec #OpenSource #Privacy

    Post summary

    The roundup highlights a kernel race‑condition flaw (Bad Epoll) with a functioning proof of concept and real‑world exploitation demonstrated, alongside an active CISA‑KEV listing for SharePoint RCE, underscoring the urgency for timely patching.

    10000474
    2.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Authorization and Authentication Vulnerability in #Apache Tomcat. CVE-2026-55956 CVSS: 6.5 and CVE-2026-55957 CVSS: 7.3 This can lead to unauthorized access. Read our advisory https://ccb.belgium.be/advisories/warning-authorization-and-authentication-vulnerabilities-apache-tomcat-patch-immediately and #Patch #Patch #Patch

    Post summary

    The post announces CVE‑2026‑55956 and CVE‑2026‑55957 in Apache Tomcat, provides CVSS scores and indicates an authorization/authentication risk, and directs readers to a patch advisory.

    01000365
    7.2K followersView on X
  • Kazuki Omo@omokazuki
    General

    Apache Tomcatの脆弱性(Important: CVE-2026-55957, Moderate: CVE-2026-55956, Low: CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE-2026-53404, CVE-2026-50229) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260630/

    Post summary

    The provided text lists multiple Apache Tomcat CVEs with severity labels but lacks details on PoC, exploitation, patches, or technical specifics.

    00010149
    369 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Apache ❗ CVE-2026-55957 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-apache-12/ https://t.co/xFBLSunNqK

    Post summary

    A brief announcement of an Apache vulnerability (CVE-2026-55957) with a link to more information, but no additional technical or exploit details provided.

    00000202
    6.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-55957 (CVSS 7.3) Apache Tomcat auth bypass via JNDIRealm/GSSAPI. Attackers can authenticate WITHOUT correct passwords. Affected: v7.0.0-11.0.4 Patch NOW to 11.0.5/10.1.37/9.0.101 #CVE #Vulnerability #PatchNow https://t.co/LAfRF9Tyus

    Post summary

    The tweet highlights a high‑severity authentication bypass (CVE‑2026‑55957) in Apache Tomcat and stresses imminent patching to specific versions.

    0000053
    56 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Two Apache Tomcat flaws (CVE-2026-55957 & CVE-2026-55956) let attackers bypass authentication by exploiting broken HTTP method-level security constraints on the default servlet-access assumed "protected" wasn't. 🔧 No workarounds exist, patch now. Upgrade to Tomcat 11.0.5/10.1.37/9.0.101+ (or 11.0.23/10.1.56/9.0.119+ for the second flaw) and audit web.xml constraints afterwards.

    Post summary

    The text announces two Apache Tomcat CVEs that allow authentication bypass due to broken method-level security, highlighting that no workarounds exist and providing specific upgrade paths for affected Tomcat versions.

    0000051
    22 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🚨 Apache Tomcat güvenlik açığı Apache Tomcat için açıklanan CVE-2026-55957 ve CVE-2026-55956 açıkları, bazı yapılandırmalarda güvenlik kontrollerinin aşılmasına neden olabiliyor. Tomcat sürümünüzü güncelleyin ve erişim kurallarınızı kontrol edin.

    Post summary

    The post alerts about two Apache Tomcat CVEs that can bypass security controls in certain configurations and urges users to update Tomcat and review access rules.

    00000194
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more