Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-53434EXPLOITEDPATCHED
apache · tomcat

Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector

Description

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

Affected Products

VendorProductVersions
apachetomcat11.0.0-M1, 10.1.0-M7, 9.0.83

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachetomcatcert_advisory90%
atlassianjiracert_advisory90%
atlassianconfluencecert_advisory90%
atlassiancruciblecert_advisory90%
atlassianbamboocert_advisory90%

References

  • https://lists.apache.org/thread/x510lbq0sfrd1qyo7q3r1mpllgpdcosk(vendor-advisory)

Related News (5 articles)

Tier D
Heise Security2d ago
Atlassian schließt mehr als 160 Sicherheitslücken in Confluence & Co.
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories54d ago
[NEU] [mittel] Apache Tomcat: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB55d ago
CVE-2026-53434 | Apache Tomcat up to 9.0.81/9.0.118/10.1.55/11.0.22 error condition
→ No new info (linked only)
Tier C
oss-security55d ago
CVE-2026-53434: Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
→ No new info (linked only)
EPSS0.00(Top 71%)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
11.0.23
CWECWE-390
PublishedJun 29, 2026
Last enriched55d agov3
Trending Score47
Source articles5
Independent4
Info Completeness9/14
Missing: cvss, epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 41
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 41
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 39
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 39
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 39

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 29, 2026
Discovered by ZDM
Jun 29, 2026
Updated: severity, affectedVersions, exploitAvailable, activelyExploited, patchAvailable
Jun 29, 2026
Updated: severity, affectedVersions
Jun 29, 2026
Actively Exploited
Jun 30, 2026
Exploit Available
Jun 30, 2026
Patch Available
Jun 30, 2026

Version History

v3
Last enriched 55d ago
v3Tier C55d ago

Updated severity to CRITICAL, added affected version 9.0.81, and noted no patch available.

severityaffectedVersions
via VulDB
v2Tier C55d ago

Updated severity to LOW, added affected version 9.0.82, and marked exploit as available and actively exploited.

severityaffectedVersionsexploitAvailableactivelyExploitedpatchAvailable
via oss-security
v155d ago

Initial creation