Multiple Vulnerabilities Found in Apache Tomcat, Four Rated Critical by CISA
Apache Tomcat has been updated to address 11 vulnerabilities, with four issues receiving a Critical rating from CISA despite lower severity assessments from the Apache development team.
The releases of Apache Tomcat 11.0.25, 10.1.59, and 9.0.121 were issued between August 18 and 20, 2026. These updates cover the previously disclosed CVE-2026-66299 along with ten additional flaws made public on August 25.
Important-rated vulnerabilities
The development team classified four vulnerabilities as Important. CVE-2026-65182 allows bypass of stricter security restrictions due to evaluation order of path-based rules. CVE-2026-65927 stems from an off-by-one error that can bypass access controls. CVE-2026-68569 permits authentication of non-existent users under certain authentication methods. CVE-2026-68763 causes resource leaks when resetting HTTP/2 streams, enabling denial-of-service conditions.
One Moderate and six Low severity issues were also resolved in the same updates.
CISA severity assessments
CISA’s CVSS v3.1 base scores differ from the vendor ratings. CVE-2026-65637 and CVE-2026-65905 received scores of 9.8, while CVE-2026-65182 and CVE-2026-68525 scored 9.1, placing all four in the Critical category. The Apache team had rated these as Moderate, Low, Important, and Low respectively.
The full list of addressed CVEs includes: CVE-2026-65182, CVE-2026-65183, CVE-2026-65637, CVE-2026-65905, CVE-2026-65927, CVE-2026-66299, CVE-2026-66422, CVE-2026-68525, CVE-2026-68569, CVE-2026-68763, and CVE-2026-73180.
Related articles
Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access
Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.
New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.
Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score
Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.
Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286
Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.