chiprook
← Security
SecurityOctober 3, 2026, 13:40

Apache Tomcat patch matrix for CVE-2026-86350

Apache fixed an Important-severity HTTP/2 request header mix-up in Tomcat, tracked as CVE-2026-86350 and caused by a regression from the CVE-2026-41293 fix. Patches ship in 11.0.26, 10.1.60 and 9.0.122; vulnerable ranges are 11.0.22–11.0.25, 10.1.55–10.1.59 and 9.0.118–9.0.121.

Apache Tomcat patch matrix for CVE-2026-86350
#Apache#Tomcat
Read next
Security

CVE-2026-77762 in Apache Tomcat: vendor rates Low, third parties 8.1

Security

Apache Tomcat 11.0.26 fixes CVE-2026-77762 HTTP/2 trailer leak

Security

Apache fixes CVE-2026-63292 in httpd 2.4.69: stack overflow in mod_vhost_alias

Security

WordPress 7.1.2 patches CVE-2026-87902 exploited within hours