Cyber Resilience
← All news

[UPDATE] [mittel] Apache Tomcat: Mehrere Schwachstellen

Our takeCERT-Bund flags multiple high-severity flaws in Apache Tomcat and Tomcat Native: remote info disclosure and security bypass. Patch if you run Tomcat; most smaller shops on hosted stacks can skip unless a vendor depends on it.
Sources (1)
What this means for you — Security leader:CERT-Bund flags multiple flaws in Apache Tomcat that let a remote unauthenticated attacker bypass security controls or disclose information. Patch to the latest 9.x, 10.x or 11.x release if you run Tomcat.
What this means for you — Lean IT orgs:If you run Apache Tomcat yourself, update it to the newest version right away. Most lean teams on hosted platforms or managed services can ignore this one.
What this means for you — MSP:Check every client Tomcat instance (self-hosted 9.x/10.x/11.x). Apply the CERT-Bund fixes promptly; hosted or containerized deployments may already be covered by the provider.
What this means for you — Researcher:CERT-Bund advisory WID-SEC-2026-2310 details multiple Tomcat flaws allowing security bypass and information disclosure by remote anonymous attackers.