Apache Tomcat patch matrix for CVE-2026-86350
Apache fixed an Important-severity HTTP/2 request header mix-up in Tomcat, tracked as CVE-2026-86350 and caused by a regression from the CVE-2026-41293 fix. Patches ship in 11.0.26, 10.1.60 and 9.0.122; vulnerable ranges are 11.0.22–11.0.25, 10.1.55–10.1.59 and 9.0.118–9.0.121.
- Vulnerable: Tomcat 11.0.22–11.0.25, 10.1.55–10.1.59, 9.0.118–9.0.121
- Fixed releases: 11.0.26, 10.1.60 and 9.0.122
- Defect is an HTTP/2 request header mix-up, a regression from the CVE-2026-41293 fix
- ZoomEye: 580,597 exposed Tomcat assets, 0 confirmed vulnerable
Read next
Security