cbcvebase.
CVE-2026-29129
published 2026-04-09

CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51…

PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.26%
17.4th percentile
Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachetomcat>= 10.1.51 < 10.1.5310.1.53
apachetomcat>= 11.0.16 < 11.0.2011.0.20
apachetomcat>= 9.0.114 < 9.0.1169.0.116
apache_software_foundationapache_tomcat10.1.51 – 10.1.52
apache_software_foundationapache_tomcat11.0.16 – 11.0.18
apache_software_foundationapache_tomcat9.0.114 – 9.0.115

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.