CRITICAL 9.8 CVE-2026-65637 Published 25 Aug 2026

Apache Tomcat HTTP Request Smuggling Bug

Worried this affects one of your servers?

Improper Input Validation vulnerability in Apache Tomcat allows HTTP Request Smuggling attacks.

Apache Tomcat versions 11.0.20 to 11.0.24, 10.1.53 to 10.1.57, and 9.0.115 to 9.0.120 are affected.

Upgrade to 11.0.25, 10.1.58, or 9.0.121 to fix the issue.

Reference: CVE-2026-65637 on NVD

← Back to Security News