Apache Released Tomcat 11.0.26 Security Update
The latest version addresses 12 newly disclosed security vulnerabilities.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust that your software providers prioritize timely security updates to protect your data?
The Apache Software Foundation has released Tomcat 11.0.26 to remediate 12 identified security vulnerabilities. These flaws impact several server components, including WebSocket, HTTP/2, and AJP.
Why it matters
Updating server software is essential to protect infrastructure against potential exploitation of these disclosed vulnerabilities. The release ensures that critical, moderate, and low-risk security gaps are closed.
This release addresses vulnerabilities across key protocols including HTTP/2, AJP, WebSocket, and TLS certificate validation. Administrators are required to apply this patch to all existing Tomcat 11 deployments.
The players
Apache Software Foundation
This non-profit corporation provides organizational, legal, and financial support for a wide range of open-source software projects.
The details
The update mitigates security risks identified in authentication processes and TLS certificate validation. Administrators must perform the update to secure their Tomcat 11 environments against the newly cataloged flaws.
Timeline
September 23, 2026: The 12 security vulnerabilities were officially disclosed.
September 24, 2026: Apache Tomcat 11.0.26 was released to the public.
The Tech Race
This update follows the established cycle of iterative security hardening for the Apache Tomcat 11 application server platform. It reflects the ongoing industry necessity of maintaining robust security postures for core middleware in an era of persistent vulnerability discovery.
Users and developers should verify if their systems utilize Tomcat 11 to ensure they are prepared for an immediate upgrade. Applying these patches protects servers from potential unauthorized access or service disruptions linked to the identified vulnerabilities.
The takeaway
Proactive patch management is a foundational requirement for securing enterprise server environments. Organizations should prioritize updating to Tomcat 11.0.26 immediately to eliminate the identified security gaps.
Further reading
For broader trends in enterprise software defense, visit the Cybersecurity section.
Live Poll
Do you trust that your software providers prioritize timely security updates to protect your data?







