VENDOR

Apache Software Foundation vulnerabilities: CVEs, exploitation and patches

Every Apache Software Foundation CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-86350
    Apache Tomcat HTTP/2 request smuggling regression Apache Software Foundation Apache Tomcat ·
    • PoC PUBLIC
    CRITICAL 9.1
  2. CVE-2026-86246
    Apache Tomcat Native insecure-default TLS options Apache Software Foundation Apache Tomcat Native ·
    CRITICAL 9.1
  3. CVE-2026-76183
    Apache Tomcat authentication bypass for WebSocket endpoints Apache Software Foundation Apache Tomcat ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-86248
    Apache Tomcat CLIENT_CERT authentication bypass (pre-auth) Apache Software Foundation Apache Tomcat ·
    CRITICAL 9.8
  5. CVE-2026-65637
    Apache Tomcat improper input validation allows remote code execution Apache Software Foundation Apache Tomcat ·
    CRITICAL 9.8
  6. CVE-2026-43825
    Apache OpenNLP LibSVM untrusted Java deserialization remote code execution Apache Software Foundation Apache OpenNLP :: Core :: ML :: LibSVM ·
    • PATCH AVAILABLE
    HIGH 7.3
  7. CVE-2026-73633
    Apache Struts JSON plugin uncontrolled resource consumption Apache Software Foundation Apache Struts ·
    • PoC PUBLIC
    HIGH 7.5
7 CVEs · page 1 of 1