DIRAS TAKE
Treat this as urgent: public exploit code exists and the flaw can be triggered without authentication, so immediately limit exposure and follow vendor mitigation guidance.
What is CVE-2026-86350?
Unauthenticated remote attackers can exploit an HTTP/2 parsing regression in Apache Tomcat to confuse how the server separates and forwards client requests, potentially allowing one client's request data to be mixed with another's and leading to high-impact request handling errors; this is tracked as CVE-2026-86350. Affected releases include Tomcat 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121. Exploitation requires only network access to a Tomcat HTTP/2 endpoint—no credentials or user interaction are needed.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of Apache Software Foundation Apache Tomcat are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.0.22 – 11.0.25 | |
| 10.x | 10.1.55 – 10.1.59 | |
| 9.x | 9.0.118 – 9.0.121 |
Is CVE-2026-86350 being exploited?
Public exploit code is available.
How to fix CVE-2026-86350
- Restrict network access to Tomcat HTTP/2 ports using firewall rules or access controls.
- Disable HTTP/2 support in Tomcat or in front-end proxies/load balancers until a vendor fix is released.
- Apply vendor guidance and announcements for official mitigations or patched releases when available.
- Monitor HTTP/2 request logs and Web server behavior for signs of request mixing and isolate affected servers.
Frequently asked questions
Is CVE-2026-86350 being actively exploited?
Public exploit code for CVE-2026-86350 is available, which increases the likelihood of active exploitation.
Which Apache Tomcat versions are affected by CVE-2026-86350?
The affected versions are 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121.
Is there a patch for CVE-2026-86350?
No fixed versions are listed in the provided facts and patchAvailable is false; follow the vendor for official patches or mitigations.
Does CVE-2026-86350 require authentication?
No, exploiting this Tomcat vulnerability does not require authentication—network access to the HTTP/2 listener is sufficient.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86350
- cve.org/CVERecord?id=CVE-2026-86350
- lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc
- All Apache Software Foundation CVEs on CVE Radar
- CVEs published in September 2026