View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities in 9, 10.1, 8.5

πŸ“‹ ADVISORIES

  • Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Affecting 9, 10.1 and 8.5
    Apache Tomcat patched 11 vulnerabilities affecting supported and end-of-life releases.
    • Apache Tomcat 9, 10.1 and 11 users are affected, along with end-of-life Tomcat 8.5.
    • Affected versions include Tomcat 9.0.0.M1–9.0.120, 10.1.0-M1–10.1.57 and 11.0.0-M1–11.0.24.
    • Important flaws enable security-constraint bypasses, RewriteValve access-control bypasses and fail-open principal lookups.
    • An HTTP/2 allocation leak triggered by stream resets can cause denial of service.
    • Other flaws affect SNI validation, DIGEST authentication, servlet roles, FORM authentication, WebSocket sessions and Unix socket permissions.
      πŸ“„ Source: tomcat.apache.org Β· πŸ“Ž Coverage: herodevs.com Β· πŸ‘ via Cyber Security News, cryptika.com (discovered)

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Reported Log4j FOIS Bypass May Enable RCE in Narrow Setups
    A reported Log4j deserialization bypass may enable RCE in narrowly configured applications.
    • Applications using Log4j serialized-event receivers are potentially affected.
    • The reported flaw bypasses FilteredObjectInputStream’s allowlist through java.rmi.MarshalledObject; no CVE is assigned.
    • A crafted serialized LogEventProxy triggers MarshalledObject.get(), which deserializes the inner payload with an unfiltered ObjectInputStream.
    • Reportedly affected versions include log4j-api 2.11.0–2.26.1 and log4j-core 2.8.0–2.26.1; exploitation requires a reachable receiver and a usable JVM gadget chain.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: sonatype.com Β· πŸ‘ via securityboulevard.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-80202 β€” CVSS 9.3 β€” Kimai before 2.56.0 Authorization Bypass via TimesheetVoterKimai before 2.56....

  • CVE-2026-80198 β€” CVSS 8.7 β€” Kimai before 2.56.0 Information Disclosure via config() Twig FunctionKimai ve...

  • CVE-2026-80197 β€” CVSS 8.7 β€” Kimai before 2.57.0 Improper Authorization via Favorite EndpointsKimai before...

  • CVE-2026-80196 β€” CVSS 8.7 β€” Kimai before 2.58.0 Authentication Bypass via Password Reset LinkKimai before...

  • CVE-2026-80195 β€” CVSS 8.7 β€” Kimai before 2.63.0 Team Membership Removal via APIKimai before 2.63.0 contai...

  • CVE-2026-80194 β€” CVSS 8.7 β€” Kimai before 2.64.0 Missing Authorization via ProjectViewController exportKim...

  • CVE-2026-80193 β€” CVSS 8.7 β€” Kimai before 2.62.0 Authorization Bypass via QuickEntryKimai before 2.62.0 fa...

  • CVE-2026-80191 β€” CVSS 8.7 β€” GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthen...

  • CVE-2026-80192 β€” CVSS 8.6 β€” better-auth SSO before 1.6.27 Domain Ownership Authentication Bypass@better-a...

  • CVE-2026-19398 β€” CVSS 6.8 β€” β€œunsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM modul...

  • CVE-2026-80199 β€” CVSS 6.3 β€” Kimai before 2.54.0 Username Enumeration via Timing OracleKimai before 2.54.0...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check