CVE-2026-59084
published 2026-07-14CVE-2026-59084: Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly…
PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.51%
41.4th percentile
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | 10.1.0 – 10.1.56 | — |
| apache | tomcat | 11.0.0 – 11.0.23 | — |
| apache | tomcat | 7.0.100 – 7.0.109 | — |
| apache | tomcat | 8.5.38 – 8.5.100 | — |
| apache | tomcat | 9.0.13 – 9.0.119 | — |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.56 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.23 | — |
| apache_software_foundation | apache_tomcat | 7.0.100 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.38 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.13 – 9.0.119 | — |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations
vendor_redhat·2026-07-14·CVSS 9.1
CVE-2026-59084 [CRITICAL] CWE-1188 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations
tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
A flaw was found in Apache Tomcat. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with ins
VulDB
Apache Tomcat up to 11.0.23 EncryptInterceptor Remote Code Execution (EUVD-2026-43640)
vuldb·2026-07-14·CVSS 9.1
CVE-2026-59084 [CRITICAL] Apache Tomcat up to 11.0.23 EncryptInterceptor Remote Code Execution (EUVD-2026-43640)
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.119/10.1.56/11.0.23. It has been classified as critical. This vulnerability affects unknown code of the component EncryptInterceptor. This manipulation causes Remote Code Execution.
This vulnerability is handled as CVE-2026-59084. The attack can be initiated remotely. There is not any exploit available.
GHSA
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
ghsa_unreviewed·2026-07-14
CVE-2026-59084 [CRITICAL] CWE-1059 Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59084 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations [fedora-all]
bugzilla·2026-07-29·CVSS 9.1
CVE-2026-59084 [CRITICAL] CVE-2026-59084 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations [fedora-all]
CVE-2026-59084 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are reco
Bugzilla
CVE-2026-59084 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations
bugzilla·2026-07-14·CVSS 9.1
CVE-2026-59084 [CRITICAL] CVE-2026-59084 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations
CVE-2026-59084 tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
2026-07-14
Published