CVE-2026-65905Disclosure(apache / tomcat)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window.   This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-294

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-08-27); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-08-26: 1Mentions · 2026-08-27: 2Mentions · 2026-09-01: 2Mentions · 2026-09-05: 1Mentions · 2026-09-09: 1Mentions · 2026-09-11: 1Mentions · 2026-09-12: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-01: 2Patch / Workaround · 2026-09-11: 1Patch / Workaround · 2026-09-12: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 2Technical Details · 2026-09-01: 2Technical Details · 2026-09-09: 1Technical Details · 2026-09-11: 1Technical Details · 2026-09-12: 108-2608-2709-0109-0509-0909-1109-12
Signal classification3 categories
Disclosure
444.4%
Patch
444.4%
General
111.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-261
Disclosure1
2026-08-272
Disclosure2
2026-09-012
Patch2
2026-09-051
General1
2026-09-091
Disclosure1
2026-09-111
Patch1
2026-09-121
Patch1
Full discourse9 posts
  • Wazuh@wazuh
    Patch

    Apache Tomcat is affected by CVE-2026-65905 (CVSS 9.8 - Critical), a DIGEST authenticator replay flaw that can allow one-time request replay. Upgrade to 11.0.25, 10.1.58, or 9.0.121. Read more: https://ow.ly/VYwQ50ZHHsR https://t.co/DIANl1Ilkv

    Post summary

    Apache Tomcat CVE-2026-65905 is a critical DIGEST authenticator replay flaw; patches are available with recommended upgrades, and no active exploitation or PoC is referenced.

    2701821.2K
    8.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-65905 Apache Tomcat DIGEST Authenticator Authentication Bypass Via Capture-Replay https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-65905

    Post summary

    The content identifies CVE‑2026‑65905 as an authentication bypass in Apache Tomcat's DIGEST Authenticator using a capture‑replay technique, without providing PoC code, exploitation reports, patches, or debunking information.

    00011145
    4.1K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    【注意】Apache TomcatのDIGEST認証にリプレイ脆弱性、更新を https://www.cybernote.click/2026/09/02/apache-tomcat-cve-2026-65905-digest-replay-bypass/ #IT #Security #cybersecurity

    Post summary

    The tweet announces a replay vulnerability (CVE-2026-65905) in Apache Tomcat's DIGEST authentication and indicates that an update/patch has been released.

    0001047
    204 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Apache Tomcat limited DIGEST authentication replay (CVE-2026-65905) If a client sent a DIGEST-authenticated request with a `nonceCount` on the upper boundary of the replay window before `windowSize` requests had been made, that request was replayable once while its `nonceCount` stayed within the window. Narrow, but an attacker who can capture traffic replays an authenticated request. CWE-294; only relevant where DIGEST auth is actually configured. 👉Affected: Tomcat 11.0.0-M1–11.0.24, 10.1.0-M1–10.1.57, 9.0.0.M1–9.0.120, plus EOL 8.5.0–8.5.100 and 7.0.30–7.0.109 | Upgrade to 11.0.25, 10.1.58, or 9.0.121

    Post summary

    CVE‑2026‑65905 exposes a replay attack in Apache Tomcat’s DIGEST authentication, affecting versions 11.0.0‑M1–11.0.24, 10.1.0‑M1–10.1.57, 9.0.0.M1–9.0.120, and older releases, with upgrades to 11.0.25, 10.1.58, or 9.0.121 recommended.

    0001096
    297 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🔁 Apache Tomcat DIGEST auth is open to replay attacks. CVE-2026-65905 (CVSS 9.8) lets attackers reuse captured nonces to bypass authentication. Check your Tomcat deployments. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-65905?utm_campaign=x https://t.co/1Q7j99Y1l4

    Post summary

    The tweet announces a new CVE-2026‑65905 affecting Apache Tomcat DIGEST authentication, describing a replay‑attack vulnerability with a high CVSS score, but it does not provide a PoC, exploit, or patch details.

    0001085
    881 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    【注意】Apache TomcatのDIGEST認証にリプレイ脆弱性、更新を https://www.cybernote.click/2026/09/02/apache-tomcat-cve-2026-65905-digest-replay-bypass/ #IT #Security #cybersecurity

    Post summary

    The tweet alerts that CVE‑2026‑65905 is a replay vulnerability in Apache Tomcat’s DIGEST authentication and recommends applying an update, but does not provide PoC, exploit code, or evidence of active exploitation.

    0000057
    204 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【注意】Apache TomcatのDIGEST認証にリプレイ脆弱性、更新を https://www.cybernote.click/2026/09/02/apache-tomcat-cve-2026-65905-digest-replay-bypass/ #IT #Security #cybersecurity

    Post summary

    The post announces a newly discovered replay vulnerability in Apache Tomcat’s Digest authentication (CVE‑2026‑65905) with a link for updates, but provides no PoC, exploit, or patch details.

    0000060
    206 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【注意】Apache TomcatのDIGEST認証にリプレイ脆弱性、更新を https://www.cybernote.click/2026/09/02/apache-tomcat-cve-2026-65905-digest-replay-bypass/ #IT #Security #cybersecurity

    Post summary

    The post warns about a replay vulnerability in Tomcat's DIGEST authentication and points to a URL for more information, without providing detail on exploitation or fixes.

    0000066
    206 followersView on X
  • Pierson-Tech@Pierson_Tech
    Patch

    @wazuh Apache rates CVE-2026-65905 Low, not Critical. It requires DIGEST authentication and a specific nonce-count condition, allowing one replay while that count remains in the window. The supported fixes are 11.0.25, 10.1.59, and 9.0.121; 10.1.58 was not released.

    Post summary

    The CVE-2026-65905 is rated low and requires DIGEST authentication with a nonce-count condition; specific Apache version fixes are provided.

    0000051
    59 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more