CVE-2026-65637: pre-auth remote code execution in Apache Software Foundation Apache Tomcat

Remote attackers can send crafted requests to Apache Tomcat and trigger an input-validation flaw that may lead to arbitrary code execution (CVE-2026-65637). Affected releases include Tomcat 11.x (11.0.20–11.0.24), 10.x (10.1.53–10.1.57) and 9.x (9.0.115–9.0.120). The vulnerability requires only network access to a reachable Tomcat listener and does not demand valid credentials or user interaction, so internet-facing or otherwise exposed instances are at risk until a vendor update is applied.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00738
CWE
CWE-20
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent — the flaw enables remote, unauthenticated code execution against exposed Tomcat services and no fixed versions are listed in the supplied data; immediately reduce exposure and watch for vendor patches.

What is CVE-2026-65637?

Remote attackers can send crafted requests to Apache Tomcat and trigger an input-validation flaw that may lead to arbitrary code execution (CVE-2026-65637). Affected releases include Tomcat 11.x (11.0.20–11.0.24), 10.x (10.1.53–10.1.57) and 9.x (9.0.115–9.0.120). The vulnerability requires only network access to a reachable Tomcat listener and does not demand valid credentials or user interaction, so internet-facing or otherwise exposed instances are at risk until a vendor update is applied.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apache Software Foundation Apache Tomcat are affected?

BRANCHAFFECTEDFIXED
11.x11.0.20 – 11.0.24
10.x10.1.53 – 10.1.57
9.x9.0.115 – 9.0.120

Is CVE-2026-65637 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-65637

  1. Block or limit network access to Tomcat ports and restrict listeners to trusted networks.
  2. Follow Apache Tomcat advisories and apply vendor patches as soon as they are published.
  3. Deploy network protections such as WAF rules and firewall filters to filter suspicious requests to Tomcat endpoints.
  4. Enable enhanced logging and monitor for anomalous requests or signs of command execution.

Frequently asked questions

Is CVE-2026-65637 being actively exploited?

There are no public reports of exploitation of CVE-2026-65637 as of 2026-09-29.

Which Apache Tomcat versions are affected by CVE-2026-65637?

Affected Tomcat releases are 11.x: 11.0.20–11.0.24; 10.x: 10.1.53–10.1.57; and 9.x: 9.0.115–9.0.120.

Is there a patch for CVE-2026-65637?

The supplied facts do not list any fixed versions; check Apache Tomcat advisories for official patches and upgrade guidance.

Does CVE-2026-65637 require authentication?

No — the issue can be triggered without authentication and only requires network access to the Tomcat service.

References