Security NEXTAugust 27, 2026🇯🇵Translated from Japanese

Multiple Vulnerabilities Found in Apache Tomcat, Four Rated Critical by CISA

Apache Tomcat has been updated to address 11 vulnerabilities, with four issues receiving a Critical rating from CISA despite lower severity assessments from the Apache development team.

The releases of Apache Tomcat 11.0.25, 10.1.59, and 9.0.121 were issued between August 18 and 20, 2026. These updates cover the previously disclosed CVE-2026-66299 along with ten additional flaws made public on August 25.

Important-rated vulnerabilities

The development team classified four vulnerabilities as Important. CVE-2026-65182 allows bypass of stricter security restrictions due to evaluation order of path-based rules. CVE-2026-65927 stems from an off-by-one error that can bypass access controls. CVE-2026-68569 permits authentication of non-existent users under certain authentication methods. CVE-2026-68763 causes resource leaks when resetting HTTP/2 streams, enabling denial-of-service conditions.

One Moderate and six Low severity issues were also resolved in the same updates.

CISA severity assessments

CISA’s CVSS v3.1 base scores differ from the vendor ratings. CVE-2026-65637 and CVE-2026-65905 received scores of 9.8, while CVE-2026-65182 and CVE-2026-68525 scored 9.1, placing all four in the Critical category. The Apache team had rated these as Moderate, Low, Important, and Low respectively.

The full list of addressed CVEs includes: CVE-2026-65182, CVE-2026-65183, CVE-2026-65637, CVE-2026-65905, CVE-2026-65927, CVE-2026-66299, CVE-2026-66422, CVE-2026-68525, CVE-2026-68569, CVE-2026-68763, and CVE-2026-73180.

Related articles

BoletimSecVulnerabilities & Exploits

SonicWall Patches Critical Path Traversal and Update Flaws in NetExtender for Linux

SonicWall has released fixes for two high-severity vulnerabilities in its NetExtender client for Linux that could allow remote attackers to write arbitrary files with root privileges and manipulate the automatic update process. The flaws impact versions 10.3.5 and earlier, while the Windows version remains unaffected. CVE-2026-66152 carries a CVSS score of 8.8 and stems from improper handling of tar archives containing OPSWAT data, enabling path traversal that lets attackers escape the intended extraction directory. CVE-2026-66153 scores 7.0 and arises from inadequate symlink and temporary file handling in the NEService update mechanism. Both issues require user interaction to exploit, and no in-the-wild attacks have been observed so far. Administrators are urged to upgrade immediately to version 10.3.6 or later, as no workarounds exist.

安全客Vulnerabilities & Exploits

Redis Patch Bypass Enables Multiple RCE Exploits as PoCs for TLS and Stream Vulnerabilities Go Public

Multiple remote code execution vulnerabilities have been disclosed in Redis over the past month, including a critical patch bypass for CVE-2026-25243 that reintroduces Double Free flaws via crafted stream operations. The latest issue, QVD-2026-58458 affecting the TLS pending list, now has full technical details and a working PoC available, following the earlier QVD-2026-55651 disclosure. All three flaws impact nearly every production version still in use, from Redis 6.2.22 and below through 7.4.9 and 8.6.4. Although authentication is required, widespread weak or empty password configurations and exposed instances make exploitation trivial for attackers. Successful compromise grants arbitrary code execution in the Redis process context, enabling standard post-exploitation steps such as credential harvesting and lateral movement across internal networks. Organizations are urged to inventory all instances, apply the latest patches immediately, restrict network access via ACLs, and monitor for anomalous use of commands like XGROUP, EVAL, and RESTORE.

Security NEXTVulnerabilities & Exploits

Cisco Pre-Announces Security Advisories and Patches for Multiple Products on September 2, 2026

Cisco Systems has disclosed plans to publish security advisories for several product lines on September 2, 2026. The advisories will cover vulnerabilities affecting IP telephony devices, network switches, and email security appliances. Targeted products include Cisco IOS XR Software, multiple series of Cisco Desk Phones, Nexus 9000 Series switches with Silicon One, and Cisco Secure Email. The company will also provide updates aimed at strengthening security in IOS XR. No CVE identifiers, vulnerability details, affected versions, or CVSS scores have been released at the pre-notification stage. Cisco strongly recommends applying the forthcoming fixes once they become available, while noting that the schedule and product scope may still change.

Security NEXTVulnerabilities & Exploits

CISA Adds Six Known Exploited Vulnerabilities Affecting NetScaler ADC, Linux Kernel and Microsoft SQL Server to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added six vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. One of the flaws, CVE-2026-8452, affects Citrix NetScaler ADC and NetScaler Gateway products and can trigger denial-of-service conditions under specific configurations. The remaining five issues, disclosed between 2015 and 2022, impact the Linux Kernel, Red Hat Automatic Bug Reporting Tool, and the libuser library. Exploitation of these older flaws can allow local attackers to escalate privileges or corrupt password files. Organizations are urged to apply available patches and verify configurations immediately.