Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-43722

CVE-2026-43722_CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be ab...

Apple iOS and iPadOS CVE
HIGH 7.5 CVE-2026-43721

CVE-2026-43721_CVE-2026-43721

This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2....

Apple Safari CVE
HIGH 8.3 CVE-2026-43701

CVE-2026-43701_CVE-2026-43701

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious w...

Apple Safari CVE
CRITICAL 9.1 CVE-2026-39868

CVE-2026-39868_CVE-2026-39868

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be abl...

Apple iOS and iPadOS CVE
HIGH 7.3 CVE-2026-55957

Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind_CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-55956

Apache Tomcat: Security constraints for default servlet ignored method_CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-55955

Apache Tomcat: EncryptInterceptor not protected against replay attacks_CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
CRITICAL 9.1 CVE-2026-53434

Apache Tomcat: Invalid CRL configuration doesn’t trigger failure for FFM Connector_CVE-2026-53434

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apa...

Apache Software Foundation Apache Tomcat 11.0.0-M1, 10.1.0-M7, 9.0.83 CVE
HIGH 7.3 CVE-2026-53404

Apache Tomcat: Bad ornext processing in RewriteValve_CVE-2026-53404

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matche...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.1 CVE-2026-50229

Apache Tomcat: XSS in number guess example_CVE-2026-50229

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE