Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-59084EXPLOITEDPATCHED
apache · tomcat

Apache Tomcat: EncryptInterceptor requirements not clearly documented

Description

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

Affected Products

VendorProductVersions
apachetomcat11.0.0-M1, 10.1.0-M1, 9.0.13, 8.5.38, 7.0.100, 10.1.57, 9.0.120, 11.0.24

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachetomcatcert_advisory90%
oraclecommunicationscert_advisory90%

References

  • https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7(vendor-advisory)

Related News (5 articles)

Tier B
BSI Advisories5d ago
[NEU] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans Apache Tomcat (15 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories40d ago
[NEU] [mittel] Apache Tomcat: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-59084 | Apache Tomcat up to 11.0.23 EncryptInterceptor Remote Code Execution
→ No new info (linked only)
Tier C
oss-security40d ago
CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
CWECWE-1059
PublishedJul 14, 2026
Last enriched39d agov3
Trending Score40
Source articles5
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 47
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 40
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 38
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 38
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 38

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, severity, activelyExploited
Jul 14, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026
Updated: affectedVersions
Jul 15, 2026

Version History

v3
Last enriched 39d ago
v3Tier B39d ago

Updated affected versions to include 10.1.57, 9.0.120, and 11.0.24, and set patchAvailable to null.

affectedVersions
via CERT-FR
v2Tier C40d ago

Updated severity to CRITICAL, changed exploit availability to false, and provided a new description detailing Remote Code Execution.

descriptionseverityactivelyExploited
via VulDB
v140d ago

Initial creation