<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Apache Tomcat (10.1.x &lt; 10.1.58) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/apache-tomcat-10.1.x--10.1.58/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 29 Jul 2026 13:55:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/apache-tomcat-10.1.x--10.1.58/feed.xml" rel="self" type="application/rss+xml"/><item><title>Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)</title><link>https://feed.craftedsignal.io/briefs/2026-07-apache-tomcat-dos-vulnerability/</link><pubDate>Wed, 29 Jul 2026 13:55:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-apache-tomcat-dos-vulnerability/</guid><description>A critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).</description><content:encoded><![CDATA[<p>A significant denial of service (DoS) vulnerability, identified as CVE-2026-66299, has been reported in multiple versions of Apache Tomcat. This flaw affects Tomcat versions 9.0.x before 9.0.121, 10.1.x before 10.1.58, and 11.0.x before 11.0.25. The vulnerability allows an unauthenticated remote attacker to disrupt the availability of the server, leading to potential operational outages. Organizations utilizing Apache Tomcat in their infrastructure are strongly advised to review their deployed versions and apply the necessary security updates to mitigate the risk of service interruption. No specific exploitation details or campaigns are mentioned in the advisory, but the nature of a remote DoS vulnerability warrants immediate attention due to the potential for significant business impact.</p>
<h2 id="impact">Impact</h2>
<p>A successful exploitation of CVE-2026-66299 would result in a denial of service condition for the affected Apache Tomcat server. This can lead to the unavailability of web applications, services, or APIs hosted on the Tomcat instance. For organizations relying on these services, the impact can range from temporary disruption of operations and loss of productivity to significant financial losses if critical business functions are affected. While the advisory does not specify the exact mechanism or ease of exploitation, any remote DoS vulnerability poses a substantial risk to service continuity and data accessibility.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-66299 by upgrading Apache Tomcat to version 9.0.121 or later, 10.1.58 or later, or 11.0.25 or later immediately. Refer to the security bulletins linked in the references for the correct patches for each affected version.</li>
<li>Regularly review the Apache Tomcat security documentation, such as <code>https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.121</code>, for updates and ensure all deployments are running supported and patched versions.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>apache-tomcat</category></item></channel></rss>