Kaspersky ID:
KLA91234
Detect Date:
08/18/2026
Updated:
08/27/2026

Description

Security bypass vulnerabilities were found in Apache Tomcat. Malicious users can exploit these vulnerabilities to bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Security vulnerability can be exploited to bypass security restrictions.
  2. Security vulnerability in HTTP/2 handling can be exploited to bypass security restrictions.
  3. Security vulnerability in security constraints can be exploited to bypass security restrictions.

Original advisories

Exploitation

Related products

CVE list

  • CVE-2026-66299
    high
  • CVE-2026-65182
    critical
  • CVE-2026-65183
    critical
  • CVE-2026-65637
    critical
  • CVE-2026-65905
    critical
  • CVE-2026-65927
    critical
  • CVE-2026-66422
    critical
  • CVE-2026-68525
    critical
  • CVE-2026-68569
    critical
  • CVE-2026-68763
    critical
  • CVE-2026-73180
    high

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Do you want to save your changes?
Your message has been sent successfully.