Exploitation observed; activity peaked at 7 mentions and remains active
Immediate actions
Patch apache tomcat systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.
Múltiples vulnerabilidades de Apache Tomcat permiten saltar la autenticación
La Apache Software Foundation ha revelado dos vulnerabilidades en Apache Tomcat (CVE-2026-55957 y CVE-2026-55956)
https://blog.elhacker.net/2026/07/multiples-vulnerabilidades-de-apache.html
Post summary
The article announces that Apache Tomcat has two newly disclosed authentication bypass vulnerabilities (CVE‑2026‑55957 and CVE‑2026‑55956).
A new authentication‑bypass flaw in Apache Tomcat’s JNDIRealm was disclosed, allowing credential‑less access; the issue has been patched alongside several other vulnerabilities.
apache CVE-2026-55957.
cloud misconfigs scale your blast radius by every region you operate in. audit IAM first.
#Apache#CVE-2026-55957
https://valtikstudios.com/blog/apache-http2-cve-2026-23918-double-free-rce-may-2026
Post summary
The text references CVE-2026-55957 but lacks technical details, proofs of exploitation, or mitigation information, resulting in a general classification.
Seven Apache Tomcat vulnerabilities are patched, including an authentication bypass (CVE-2026-55957). Update to a fixed Tomcat release now.
#ApacheTomcat#Tomcat#CVE202655957#AuthenticationBypass#JNDIRealm#WebServerSecurity#Vulnerability
https://securityonline.info/apache-tomcat-vulnerabilities-cve-2026-55957 https://t.co/TF11wBWHrm
Post summary
The tweet announces that seven Apache Tomcat vulnerabilities, including CVE-2026-55957, have been patched and urges users to update to a fixed release.
The article announces two CVEs in Apache Tomcat that allow authentication bypass and recommends applying vendor patches and reviewing access‑control settings.
The post discloses technical details of two Tomcat CVEs, highlights their narrow exploitable conditions, and advises migration or upgrading but does not provide PoC, exploit code, or evidence of active exploitation.
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 04, 2026
1️⃣ "BAD EPOLL" LINUX KERNEL VULNERABILITY HITS 6.4+ AND ANDROID WITH 99% RELIABILITY
A critical race condition flaw named "Bad Epoll" (CVE-2026-46242) has been discovered in Linux kernel versions 6.4 and above, affecting a wide range of modern Linux distributions and newer Android devices. The vulnerability allows any unprivileged local user to escalate to full root access. The proof-of-concept achieves a remarkable 99% success rate and can potentially be triggered from Chrome's renderer sandbox, making exploitation from a compromised web page feasible. Security teams should audit kernel versions and apply available patches immediately.
🔹 @TheHackersNews
2️⃣ BAD EPOLL: THE KERNEL BUG MISSED BY MYTHOS — REAL-WORLD EXPLOIT DEMONSTRATED
Security researcher Jaeyoung Chung detailed his exploitation of CVE-2026-46242, using the race condition in the eventpoll subsystem to claim a kernelCTF challenge. The vulnerability is not just theoretical — it also affects production Android kernels, meaning the attack surface extends far beyond desktop Linux systems. The exploit's high reliability underscores the seriousness of eventpoll race conditions in modern kernel implementations.
🔹 @linkersec
3️⃣ CISA ADDS MICROSOFT SHAREPOINT RCE TO KNOWN EXPLOITED VULNERABILITIES CATALOG
CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, flagging an active remote code execution vulnerability in Microsoft SharePoint Server. The flaw stems from unsafe deserialization of untrusted data, allowing attackers to execute arbitrary code on on-premises SharePoint installations. Active exploitation has been confirmed in the wild, making immediate patching essential for any organization running SharePoint Server.
🔹 @CISACyber
4️⃣ CISA ISSUES THREE NEW AND THREE UPDATED ICS SECURITY ADVISORIES
The Cybersecurity and Infrastructure Security Agency released three new public ICS (Industrial Control Systems) advisories alongside three updated ones. These advisories cover current security issues, vulnerabilities, and active exploits targeting industrial control systems — infrastructure that powers everything from energy grids to manufacturing facilities. Organizations operating ICS environments should review the full advisories on CISA's portal and assess their exposure.
🔹 @CISACyber
5️⃣ PEAR RANSOMWARE GROUP TARGETS SG'S CNW ELECTRONICS AND US BEVERAGE COMPANY
The PEAR ransomware operation has added two new victims to its dark web data leak portal: CNW Electronics based in Singapore, a critical electronics sector company, and AC Beverage, Inc. in the United States. Reports indicate that approximately 4.6 terabytes of data were stolen from CNW Electronics alone. The group continues to demonstrate a pattern of targeting companies in critical infrastructure and supply chain sectors.
🔹 @FalconFeedsio
6️⃣ APACHE TOMCAT AUTHENTICATION BYPASS VULNERABILITY AFFECTS VERSIONS 7 THROUGH 11
CVE-2026-55957 is an authentication bypass vulnerability in Apache Tomcat that allows password-free login when GSSAPI-based authentication is configured. The flaw impacts a broad range of Tomcat versions spanning from 7 through 11, affecting installations that rely on GSSAPI for authentication. While active exploitation has not yet been confirmed, the wide version coverage makes this a priority for administrators running GSSAPI-configured Tomcat servers.
🔹 @MalwareBibleJP
7️⃣ BLOODHOUND ENTERPRISE HYGIENE FINDINGS: BEYOND ATTACK PATHS
SpecterOps highlighted a powerful feature of BloodHound Enterprise — the Hygiene findings module. Unlike traditional attack path analysis that shows how adversaries reach their objective, Hygiene findings surface the underlying conditions attackers exploit: oversized default groups with delegated privileges, AS-REP roastable accounts, and Kerberoastable accounts. These hygiene issues may not be direct attack paths, but eliminating them removes the foundation that makes lateral movement and privilege escalation possible.
🔹 @SpecterOps
💭 The cybersecurity landscape this week is dominated by kernel-level threats and supply chain risks. The Bad Epoll vulnerability demonstrates how even fundamental OS primitives can harbor devastating race conditions, while CISA's KEV additions and ICS advisories remind us that critical infrastructure remains a top target. The common thread across all these stories is the need for proactive hygiene — patching, monitoring, and understanding the conditions that turn theoretical vulnerabilities into active exploits.
Which of these vulnerabilities keeps you up at night — kernel exploits, ransomware campaigns, or ICS threats? Let me know below 👇
#Cybersecurity#CVE#LinuxKernel#Ransomware#CISA#InfoSec#OpenSource#Privacy
Post summary
The roundup highlights a kernel race‑condition flaw (Bad Epoll) with a functioning proof of concept and real‑world exploitation demonstrated, alongside an active CISA‑KEV listing for SharePoint RCE, underscoring the urgency for timely patching.
Warning: Authorization and Authentication Vulnerability in #Apache Tomcat. CVE-2026-55956 CVSS: 6.5 and CVE-2026-55957 CVSS: 7.3 This can lead to unauthorized access. Read our advisory https://ccb.belgium.be/advisories/warning-authorization-and-authentication-vulnerabilities-apache-tomcat-patch-immediately and #Patch#Patch#Patch
Post summary
The post announces CVE‑2026‑55956 and CVE‑2026‑55957 in Apache Tomcat, provides CVSS scores and indicates an authorization/authentication risk, and directs readers to a patch advisory.
⚠️ Vulnerabilidad en productos Apache
❗ CVE-2026-55957
➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-apache-12/ https://t.co/xFBLSunNqK
Post summary
A brief announcement of an Apache vulnerability (CVE-2026-55957) with a link to more information, but no additional technical or exploit details provided.
🚨 HIGH SEVERITY: CVE-2026-55957 (CVSS 7.3)
Apache Tomcat auth bypass via JNDIRealm/GSSAPI. Attackers can authenticate WITHOUT correct passwords.
Affected: v7.0.0-11.0.4
Patch NOW to 11.0.5/10.1.37/9.0.101
#CVE#Vulnerability#PatchNow https://t.co/LAfRF9Tyus
Post summary
The tweet highlights a high‑severity authentication bypass (CVE‑2026‑55957) in Apache Tomcat and stresses imminent patching to specific versions.
🚨 Two Apache Tomcat flaws (CVE-2026-55957 & CVE-2026-55956) let attackers bypass authentication by exploiting broken HTTP method-level security constraints on the default servlet-access assumed "protected" wasn't.
🔧 No workarounds exist, patch now. Upgrade to Tomcat 11.0.5/10.1.37/9.0.101+ (or 11.0.23/10.1.56/9.0.119+ for the second flaw) and audit web.xml constraints afterwards.
Post summary
The text announces two Apache Tomcat CVEs that allow authentication bypass due to broken method-level security, highlighting that no workarounds exist and providing specific upgrade paths for affected Tomcat versions.
🚨 Apache Tomcat güvenlik açığı
Apache Tomcat için açıklanan CVE-2026-55957 ve CVE-2026-55956 açıkları, bazı yapılandırmalarda güvenlik kontrollerinin aşılmasına neden olabiliyor.
Tomcat sürümünüzü güncelleyin ve erişim kurallarınızı kontrol edin.
Post summary
The post alerts about two Apache Tomcat CVEs that can bypass security controls in certain configurations and urges users to update Tomcat and review access rules.