Apache Patched 12 Vulnerabilities in Tomcat 11.0.26
The release addresses critical flaws in WebSocket, HTTP/2, and TLS that require immediate server updates.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust that your software providers prioritize timely security updates to protect your data?
The Apache Software Foundation has released Tomcat 11.0.26 to resolve 12 distinct security vulnerabilities disclosed on September 23, 2026. This update is now available for all administrators managing Tomcat 11 server deployments.
Why it matters
Timely patching of these server-side flaws is essential to preventing potential unauthorized access or service disruptions across enterprise web infrastructure. These vulnerabilities impact core communication protocols, including HTTP/2 and TLS certificate validation, necessitating an immediate transition to the latest version.
The update mitigates 12 vulnerabilities, categorized as four Important, three Moderate, and five Low severity. These flaws impact critical stack components including WebSocket, HTTP/2, AJP, authentication processes, and TLS certificate validation.
The players
Apache Software Foundation
A non-profit corporation providing software for the public good, responsible for maintaining the widely used open-source Tomcat application server.
The details
The patches target flaws in the server architecture that facilitate secure communication. By updating to version 11.0.26, administrators secure their handling of WebSocket—a protocol for full-duplex communication channels—and HTTP/2 traffic. The fixes also address inconsistencies in how the server performs TLS certificate validation—the digital process used to verify the identity of a website or server—ensuring encrypted connections remain resistant to unauthorized interception.
Timeline
September 23, 2026: The 12 security vulnerabilities were officially disclosed.
September 24, 2026: Apache Tomcat 11.0.26 was released to the public.
The Tech Race
This release follows the industry standard of rapid remediation for foundational server software. It mirrors the urgency seen in the 2021 Log4j vulnerability disclosures, where maintaining the security of ubiquitous open-source infrastructure remains a persistent challenge.
System administrators must prioritize upgrading existing Tomcat 11 deployments to version 11.0.26 immediately to protect their server environments. This update changes the security posture of any application relying on WebSocket or HTTP/2 protocols, requiring a standard patch cycle to implement.
The takeaway
Security managers should cross-reference their server versions to ensure they are no longer running the vulnerable 11-series build. Future security disclosures from the Apache Software Foundation should be monitored to track any remaining edge-case risks within the Tomcat 11 ecosystem.
Further reading
For broader trends in server protection and software integrity, visit Cybersecurity.
Live Poll
Do you trust that your software providers prioritize timely security updates to protect your data?







