cbcvebase.
CVE-2026-32990
published 2026-08-25

CVE-2026-32990: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through…

PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.31%
23.0th percentile
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat>= 10.1.50 < 10.1.5310.1.53
apachetomcat>= 10.1.53 < 10.1.5810.1.58
apachetomcat>= 11.0.15 < 11.0.2011.0.20
apachetomcat>= 11.0.20 < 11.0.2511.0.25
apachetomcat>= 9.0.113 < 9.0.1169.0.116
apachetomcat>= 9.0.115 < 9.0.1219.0.121
apache_software_foundationapache_tomcat10.1.53 – 10.1.57
apache_software_foundationapache_tomcat11.0.20 – 11.0.24
apache_software_foundationapache_tomcat9.0.115 – 9.0.120
debiantomcat10
debiantomcat11
debiantomcat9
pki-deps_10.6pki-servlet-engine

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa9.1CRITICAL
vendor_apache9.1
vendor_redhat9.1CRITICAL
vendor_oracle8.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.