CVE-2026-41293: Apache Tomcat

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

Affected products

  • Apache Tomcat: from 8.5.0, up to and including 8.5.100; from 9.0.0, before 9.0.118 (fixed in 9.0.118); from 10.0.0, up to and including 10.0.27; from 10.1.0, before 10.1.55 (fixed in 10.1.55); from 11.0.0, before 11.0.22 (fixed in 11.0.22)

Published 2026-05-12. Last modified 2026-06-17.