DIRAS TAKE
Treat this as urgent — the flaw enables remote, unauthenticated code execution against exposed Tomcat services and no fixed versions are listed in the supplied data; immediately reduce exposure and watch for vendor patches.
What is CVE-2026-65637?
Remote attackers can send crafted requests to Apache Tomcat and trigger an input-validation flaw that may lead to arbitrary code execution (CVE-2026-65637). Affected releases include Tomcat 11.x (11.0.20–11.0.24), 10.x (10.1.53–10.1.57) and 9.x (9.0.115–9.0.120). The vulnerability requires only network access to a reachable Tomcat listener and does not demand valid credentials or user interaction, so internet-facing or otherwise exposed instances are at risk until a vendor update is applied.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apache Software Foundation Apache Tomcat are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.0.20 – 11.0.24 | |
| 10.x | 10.1.53 – 10.1.57 | |
| 9.x | 9.0.115 – 9.0.120 |
Is CVE-2026-65637 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-65637
- Block or limit network access to Tomcat ports and restrict listeners to trusted networks.
- Follow Apache Tomcat advisories and apply vendor patches as soon as they are published.
- Deploy network protections such as WAF rules and firewall filters to filter suspicious requests to Tomcat endpoints.
- Enable enhanced logging and monitor for anomalous requests or signs of command execution.
Frequently asked questions
Is CVE-2026-65637 being actively exploited?
There are no public reports of exploitation of CVE-2026-65637 as of 2026-09-29.
Which Apache Tomcat versions are affected by CVE-2026-65637?
Affected Tomcat releases are 11.x: 11.0.20–11.0.24; 10.x: 10.1.53–10.1.57; and 9.x: 9.0.115–9.0.120.
Is there a patch for CVE-2026-65637?
The supplied facts do not list any fixed versions; check Apache Tomcat advisories for official patches and upgrade guidance.
Does CVE-2026-65637 require authentication?
No — the issue can be triggered without authentication and only requires network access to the Tomcat service.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65637
- cve.org/CVERecord?id=CVE-2026-65637
- lists.apache.org/thread/djog953z1ohsyt25bdvhfzbmsy22vgcj
- All Apache Software Foundation CVEs on CVE Radar
- CVEs published in September 2026