Cyber Resilience
← All news

[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellen

CERT-Bund flags multiple high-severity flaws in Apache Tomcat and Tomcat Native: remote info disclosure and security bypass. Patch if you run Tomcat; most smaller shops on hosted stacks can skip unless a vendor depends on it.
Sources (42)
What this means for you — CISO:Inventory Apache Tomcat and Tomcat Native across the estate and patch internet-facing instances first — CERT-Bund rates remote unauthenticated info disclosure and security-bypass flaws as high. Fold the concurrent Linux kernel and Firefox/Thunderbird advisories into the normal prioritization queue.
What this means for you — Lean IT orgs:If you self-host Java apps on Apache Tomcat, update Tomcat and Tomcat Native now; if a host or vendor runs them for you, ask whether they have applied the fixes. Same pass: keep Firefox/Thunderbird and your OS current if you manage those yourself.
What this means for you — MSP:Scan client estates for Tomcat and Tomcat Native, prioritize internet-facing and multi-tenant hosts, and verify Tomcat Native (APR/OpenSSL) versions where in use. Batch the parallel kernel and Mozilla advisories into the same patch window per client risk.
What this means for you — Researcher:CERT-Bund WID-SEC-2026-0443 flags multiple Tomcat/Tomcat Native issues enabling remote unauthenticated info disclosure and control bypass; adjacent WID items cover Linux kernel and Mozilla Firefox/Thunderbird/ESR flaw sets worth diffing against upstream advisories.