CRITICAL 9.1 CVE-2026-86350 Published 23 Sept 2026

Apache Tomcat HTTP/2 Request Smuggling Vulnerability

Worried this affects your website?

Apache Tomcat is affected by an HTTP/2 request smuggling vulnerability caused by a regression in the fix for CVE-2026-41293, which can trigger request header mix-up.

The issue affects the following versions:

  • 11.0.22 through 11.0.25
  • 10.1.55 through 10.1.59
  • 9.0.118 through 9.0.121

Users are recommended to upgrade to 11.0.26, 10.1.60, or 9.0.122.

Reference: CVE-2026-86350 on NVD

← Back to Security News