cbcvebase.
CVE-2026-32990
published 2026-04-09

CVE-2026-32990: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through…

PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.31%
23.0th percentile
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 10.1.50 < 10.1.5310.1.53
apachetomcat>= 11.0.15 < 11.0.2011.0.20
apachetomcat>= 9.0.113 < 9.0.1169.0.116

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa9.1CRITICAL
vendor_apache9.1
vendor_redhat9.1CRITICAL
vendor_oracle8.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.