Exposure of Apache Tomcat

Web servers
431
exposure score
14,239
sites use
6
exploited
27
critical
Vexday analysis

Apache Tomcat acumula 131 CVEs catalogadas, das quais 5 estão confirmadas em exploração ativa pelo CISA KEV — representando uma taxa 8,5 vezes acima da média geral do catálogo, sinal claro de que vulnerabilidades nessa tecnologia atraem atenção consistente de agentes maliciosos. O tipo de falha mais recorrente é CWE-20 (validação de entrada imprópria), que historicamente viabiliza desde execução remota de código até desvios de controle de acesso. A CVE mais crítica atualmente ativa, CVE-2017-12617, apresenta EPSS de 0,9999 — praticamente a pontuação máxima de probabilidade de exploração —, exigindo atenção prioritária em qualquer ambiente que ainda execute versões vulneráveis. Os 17 novos registros surgidos nos últimos 90 dias, somados às 19 CVEs de severidade crítica, indicam uma superfície de ataque que segue crescendo e que demanda ciclos de patching frequentes e monitoramento contínuo.

CVEs

151 results
CVE-2026-66299HIGHApache Tomcat: DoS via WebSocket chat exampleEPSS 0.5%CVE-2026-25854MEDIUMApache Tomcat: Occasionally open redirectEPSS 0.5%CVE-2026-68569HIGHApache Tomcat: Principal lookup can fail open in some casesEPSS 0.5%CVE-2026-24880HIGHApache Tomcat: Request smuggling via invalid chunk extensionEPSS 0.5%CVE-2026-24734HIGHApache Tomcat Native, Apache Tomcat: OCSP revocation bypassEPSS 0.5%CVE-2026-24733MEDIUMApache Tomcat: Security constraint bypass with HTTP/0.9EPSS 0.5%CVE-2026-59084CRITICALApache Tomcat: EncryptInterceptor requirements not clearly documentedEPSS 0.5%CVE-2026-43513HIGHApache Tomcat: LockOutRealm treats user names as case-sensitiveEPSS 0.5%CVE-2025-40711CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.5%CVE-2026-34500MEDIUMApache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabledEPSS 0.5%CVE-2026-34483HIGHApache Tomcat: Incomplete escaping of JSON access logsEPSS 0.5%CVE-2026-65183HIGHApache Tomcat: TOCTOU when setting specific permissions for Unix Domain SocketsEPSS 0.5%CVE-2026-34487HIGHApache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer tokenEPSS 0.4%CVE-2026-55955MEDIUMApache Tomcat: EncryptInterceptor not protected against replay attacksEPSS 0.4%CVE-2025-40712CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.4%CVE-2025-40713CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.4%CVE-2025-40715CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.4%CVE-2025-40717CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.4%CVE-2025-40716CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.4%CVE-2025-40714CRITICALSQL injection vulnerability in Quiter GatewayEPSS 0.4%