CVE-2026-76183

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 4 mentions (2026-09-23); latest day: 2
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-09-23: 4Mentions · 2026-09-24: 209-2309-24
Referenced assets5 URLs
Full discourse6 posts
  • Kazuki Omo@omokazuki

    Tomcatの脆弱性(Critical: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, High: CVE-2026-75973, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-87022, Medium: CVE-2026-73581, Low: CVE-2026-77756) https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260924/

    00012124
    372 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs

    CVE-2026-76183 Apache Tomcat Authentication bypass could expose protected WebSocket endpoints on affected public-facing Tomcat servers Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-09-23/TIER_2_CVE-2026-76183.md #CyberSecurity #WebSecurity #VulnerabilityManagement

    0000012
    62 followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Apache Tomcat: Kritische WebSocket-Lücke CVE-2026-76183 erlaubt Umgehung der Authentifizierung #apache #apachetomcat #cve202676183 #websocket https://cybersecurity-news.de/apache-tomcat-cve-2026-76183-websocket-authentifizierung-umgehung

    0000016
    12 followersView on X
  • SecAlerts@SecAlertsCo

    🪣 Apache Tomcat CVE-2026-76183: critical 9.8 auth bypass lets attackers skip security constraints on ANY WebSocket endpoint. No auth, no interaction needed. Patch now if you're on Tomcat 11.0.0-M1+. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-76183?utm_campaign=x https://t.co/0tLocBDGwn

    0000062
    888 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Apache Tomcat WebSocket Auth Bypass via Alternate Name (CVE-2026-76183) Apache Tomcat WebSocket security constraints can be bypassed when an endpoint is accessed via an alternate name, allowing attackers to reach protected WS endpoints without auth. Impacts constraint enforcement for WebSocket mappings across multiple branches. 👉Affected: Apache Tomcat 11.0.x, 10.1.x, 9.0.x, 8.5.x, 7.0.x | Upgrade to 11.0.26 / 10.1.60 / 9.0.122

    0000069
    305 followersView on X
  • CVE@CVEnew

    CVE-2026-76183 Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affec… https://www.cve.org/CVERecord?id=CVE-2026-76183

    00000822
    58.1K followersView on X

Explore more