Apache Tomcat Security Update – 15 July 2026

Apache Tomcat has released a security update to address two vulnerabilities affecting multiple versions of Apache Tomcat.

The addressed vulnerabilities could allow the attacker to obtain sensitive information or bypass security restrictions on the affected system.

The addressed vulnerabilities:

1. Apache Tomcat Improper Handling of URL Encoding Vulnerability (CVE-2026- 59083):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

2. Apache Tomcat Insufficient Technical Documentation Vulnerability (CVE- 2026-59084):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2026-59083
  • CVE-2026-59084
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apache Tomcat Security Advisory

References