Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY126 SECURITY RECORDS

Apache Software Foundation

Apache Tomcat

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-87022 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.0.M1 ≤ 9.0.121, 8.5.0 ≤ 8.5.100, 7.0.56 ≤ 7.0.109 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-86350 23 Sep 2026 Apache Tomcat: 11.0.22 ≤ 11.0.25, 10.1.55 ≤ 10.1.59, 9.0.118 ≤ 9.0.121 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-86248 23 Sep 2026 Apache Tomcat: 11.0.0-M14 ≤ 11.0.25, 10.1.22 ≤ 10.1.59, 9.0.92 ≤ 9.0.121 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-79677 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.0.M1 ≤ 9.0.121, 8.5.0 ≤ 8.5.100, 7.0.43 ≤ 7.0.109 Apache Tomcat: < 7.0.43 Update reference ↗
CVE-2026-78437 23 Sep 2026 Apache Tomcat: 11.0.19 ≤ 11.0.25, 10.1.53 ≤ 10.1.59, 9.0.116 ≤ 9.0.121 Apache Tomcat: ≤ 8.5.100 Update reference ↗
CVE-2026-78383 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.0.M1 ≤ 9.0.121, 8.5.0 ≤ 8.5.100, 7.0.0 ≤ 7.0.109 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-77791 23 Sep 2026 Apache Tomcat: 11.0.0-M5 ≤ 11.0.25, 10.1.8 ≤ 10.1.59, 9.0.74 ≤ 9.0.121, 8.5.88 ≤ 8.5.100 Apache Tomcat: ≤ 7.0.109 Update reference ↗
CVE-2026-77762 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.39 ≤ 9.0.121, 8.5.59 ≤ 8.5.100 Apache Tomcat: ≤ 7.0.109 Update reference ↗
CVE-2026-77756 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.47 ≤ 9.0.121, 8.5.67 ≤ 8.5.100 Apache Tomcat: ≤ 7.0.109 Update reference ↗
CVE-2026-76183 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.0.M1 ≤ 9.0.121, 8.5.0 ≤ 8.5.100, 7.0.43 ≤ 7.0.109 Apache Tomcat: < 7.0.43 Update reference ↗
CVE-2026-75973 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.0.M4 ≤ 9.0.121, 8.5.0 ≤ 8.5.100 Apache Tomcat: ≤ 7.0.109 Update reference ↗
CVE-2026-73581 23 Sep 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.25, 10.1.0-M1 ≤ 10.1.59, 9.0.0.M1 ≤ 9.0.121, 8.5.0 ≤ 8.5.100 Apache Tomcat: < 8.5.0 Update reference ↗
CVE-2026-73180 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.0.M1 ≤ 9.0.120; 8.5.0 ≤ 8.5.100; 7.0.43 ≤ 7.0.109 < 7.0.43 Update reference ↗
CVE-2026-68763 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.39 ≤ 9.0.120; 8.5.59 ≤ 8.5.100 ≤ 7.0.109 Update reference ↗
CVE-2026-68569 25 Aug 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.24, 10.1.0-M1 ≤ 10.1.57, 9.0.0.M1 ≤ 9.0.120, 8.5.0 ≤ 8.5.100, 7.0.0 ≤ 7.0.109, < 7.0.0 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-68525 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.0.M1 ≤ 9.0.120; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-66422 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.25 ≤ 9.0.120; 8.5.46 ≤ 8.5.100; 7.0.97 ≤ 7.0.109 < 7.0.97 Update reference ↗
CVE-2026-65927 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.0.M1 ≤ 9.0.120; 8.5.0 ≤ 8.5.100 7.0.0 ≤ 7.0.109; < 7.0.0 Update reference ↗
CVE-2026-65905 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.0.M1 ≤ 9.0.120; 8.5.0 ≤ 8.5.100; 7.0.30 ≤ 7.0.109 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-65637 25 Aug 2026 11.0.20 ≤ 11.0.24; 10.1.53 ≤ 10.1.57; 9.0.115 ≤ 9.0.120 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-65183 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.42 ≤ 9.0.120 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109 Update reference ↗
CVE-2026-65182 25 Aug 2026 11.0.0-M1 ≤ 11.0.24; 10.1.0-M1 ≤ 10.1.57; 9.0.0.M1 ≤ 9.0.120; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-66299 28 Jul 2026 11.0.0-M20 ≤ 11.0.24; 10.1.24 ≤ 10.1.57; 9.0.89 ≤ 9.0.120 ≤ 8.5.100 Update reference ↗
CVE-2026-59084 14 Jul 2026 11.0.0-M1 ≤ 11.0.23; 10.1.0-M1 ≤ 10.1.56; 9.0.13 ≤ 9.0.119; 8.5.38 ≤ 8.5.100; 7.0.100 ≤ 7.0.109 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-59083 14 Jul 2026 11.0.0-M1 ≤ 11.0.23; 10.1.0-M1 ≤ 10.1.56; 9.0.0.M1 ≤ 9.0.119; 8.5.0 ≤ 8.5.100 < 8.0.0 Update reference ↗
CVE-2026-55957 29 Jun 2026 11.0.0-M1 ≤ 11.0.4; 10.1.0-M1 ≤ 10.1.36; 9.0.0.M1 ≤ 9.0.100; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-55956 29 Jun 2026 11.0.0-M1 ≤ 11.0.22; 10.1.0-M1 ≤ 10.1.55; 9.0.0.M1 ≤ 9.0.118; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-55955 29 Jun 2026 11.0.0-M1 ≤ 11.0.22; 10.1.0-M1 ≤ 10.1.55; 9.0.13 ≤ 9.0.118; 8.5.38 ≤ 8.5.100; 7.0.100 ≤ 7.0.109 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-55276 29 Jun 2026 11.0.0-M1 ≤ 11.0.22; 10.1.0-M1 ≤ 10.1.55; 9.0.0.M1 ≤ 9.0.118; 8.5.0 ≤ 8.5.100 < 8.0.0 Update reference ↗
CVE-2026-53434 29 Jun 2026 11.0.0-M1 ≤ 11.0.22; 10.1.0-M7 ≤ 10.1.55; 9.0.83 ≤ 9.0.118 ≤ 9.0.82 Update reference ↗
CVE-2026-53404 29 Jun 2026 11.0.0-M1 ≤ 11.0.22; 10.1.0-M1 ≤ 10.1.55; 9.0.0.M1 ≤ 9.0.118; 8.5.0 ≤ 8.5.100 < 8.0.0 Update reference ↗
CVE-2026-50229 29 Jun 2026 11.0.0-M1 ≤ 11.0.22; 10.1.0-M1 ≤ 10.1.55; 9.0.0.M1 ≤ 9.0.118; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-43515 12 May 2026 11.0.0-M1 ≤ 11.0.21; 10.1.0-M1 ≤ 10.1.54; 9.0.0.M1 ≤ 9.0.117; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-43514 12 May 2026 11.0.0-M1 ≤ 11.0.21; 10.1.0-M1 ≤ 10.1.54; 9.0.0.M1 ≤ 9.0.117; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.00 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-43513 12 May 2026 11.0.0-M1 ≤ 11.0.21; 10.1.0-M1 ≤ 10.1.54; 9.0.0.M1 ≤ 9.0.117; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.00 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-43512 12 May 2026 11.0.0-M1 ≤ 11.0.21; 10.1.0-M1 ≤ 10.1.54; 9.0.0.M1 ≤ 9.0.117; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-41293 12 May 2026 Apache Tomcat: 11.0.0-M1 ≤ 11.0.21, 10.1.0-M1 ≤ 10.1.54, 9.0.0.M1 ≤ 9.0.117, 10.0.0-M1 ≤ 10.0.27, 8.5.0 ≤ 8.5.100 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-42498 12 May 2026 11.0.0-M1 ≤ 11.0.21; 10.1.0-M1 ≤ 10.1.54; 9.0.2 ≤ 9.0.117; 8.5.24 ≤ 8.5.100; 7.0.83 ≤ 7.0.109 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-41284 12 May 2026 11.0.0-M1 ≤ 11.0.21; 10.1.0-M1 ≤ 10.1.54; 9.0.0.M1 ≤ 9.0.117; 10.0.0-M1 ≤ 10.0.27; 8.5.0 ≤ 8.5.100; 4.0 ≤ 7.0.109 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-34500 9 Apr 2026 11.0.0-M14 ≤ 11.0.20; 10.1.22 ≤ 10.1.53; 9.0.92 ≤ 9.0.116 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-34487 9 Apr 2026 11.0.0-M1 ≤ 11.0.20; 10.1.0-M1 ≤ 10.1.53; 9.0.13 ≤ 9.0.116 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-34483 9 Apr 2026 11.0.0-M1 ≤ 11.0.20; 10.1.0-M1 ≤ 10.1.53; 9.0.40 ≤ 9.0.116; 8.5.84 ≤ 8.5.100 ≤ 8.5.83 Update reference ↗
CVE-2026-32990 9 Apr 2026 11.0.15 ≤ 11.0.19; 10.1.50 ≤ 10.1.52; 9.0.113 ≤ 9.0.115 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-29146 9 Apr 2026 11.0.0-M1 ≤ 11.0.18; 10.0.0-M1 ≤ 10.1.52; 9.0.13 ≤ 9.0.115; 8.5.38 ≤ 8.5.100; 7.0.100 ≤ 7.0.109 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-29145 9 Apr 2026 11.0.0-M1 ≤ 11.0.18; 10.1.0-M7 ≤ 10.1.52; 9.0.83 ≤ 9.0.115; 1.1.23 ≤ 1.1.34; 1.2.0 ≤ 1.2.39; 1.3.0 ≤ 1.3.6; 2.0.0 ≤ 2.0.13 ≤ 8.5.100 Update reference ↗
CVE-2026-29129 9 Apr 2026 11.0.16 ≤ 11.0.18; 10.1.51 ≤ 10.1.52; 9.0.114 ≤ 9.0.115 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-25854 9 Apr 2026 11.0.0-M1 ≤ 11.0.18; 10.1.0-M1 ≤ 10.1.52; 9.0.0.M23 ≤ 9.0.115; 8.5.30 ≤ 8.5.100 ≤ 7.0.109 Update reference ↗
CVE-2026-24880 9 Apr 2026 11.0.0-M1 ≤ 11.0.18; 10.1.0-M1 ≤ 10.1.52; 9.0.0.M1 ≤ 9.0.115; 8.5.0 ≤ 8.5.100; 7.0.0 ≤ 7.0.109; < 7.0.0; 8.0.0-RC1 ≤ 8.0.53 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-24733 17 Feb 2026 11.0.0-M1 ≤ 11.0.14; 10.1.0-M1 ≤ 10.1.49; 9.0.0.M1 ≤ 9.0.112; ≤ 8.5.100 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2025-66614 17 Feb 2026 11.0.0-M1 ≤ 11.0.14; 10.1.0-M1 ≤ 10.1.49; 9.0.0-M1 ≤ 9.0.112; 8.5.0 ≤ 8.5.100 < 8.5.0 Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.