CVE-2026-59084 – Apache Tomcat

CVSS 9.1 CRITICAL 2 Critical – Same Day Deployment

“Even strong security features fail when secure configuration isn't clearly defined.”

A patch is available for CVE-2026-59084, a vulnerability affecting Apache Tomcat. The issue stems from insufficient technical documentation for securely configuring the EncryptInterceptor, which could leave deployments vulnerable if the feature is not configured correctly. The vulnerability is associated with CWE-1059 (Insufficient Technical Documentation).

The issue affects Apache Tomcat 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Users should upgrade to Apache Tomcat 11.0.24, 10.1.57, or 9.0.120, which address the issue.

The CVSS score is 9.1, which is Critical severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Key Details

Affected Product
Apache Tomcat
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-1059
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.