Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Apache Tomcat Security Constraint Bypass Vulnerability

Apache Tomcat's security team has released security updates addressing multiple vulnerabilities, including (CVE-2026-65182), a security constraint bypass vulnerability in Apache Tomcat's request-authorization processing. If exploited, this vulnerability could allow an attacker to bypass authentication and security controls on affected systems.
 
Affected Systems:
  • Apache Tomcat versions from 9.0.0.M1 to 9.0.120
  • Apache Tomcat versions from 10.1.0-M1 to 10.1.57
  • Apache Tomcat versions from 11.0.0-M1 to 11.0.24
 
Security Risks
 
Successful exploitation of this vulnerability could allow an unauthenticated attacker to bypass Tomcat’s security constraints and access protected application resources.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Apply the latest supported security updates for affected Apache Tomcat Software as soon as possible to address these known vulnerabilities.
 
2. Upgrade to the following supported versions:
 
3. Migrate away from unsupported versions (Tomcat 7.0.x / 8.5.x) to a supported release, since no security fixes are available for end-of-life branches.
 
4. Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

01 September 2026

© 2026 National Cyber Security Authority