π ADVISORIES
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Affecting 9, 10.1 and 8.5
Apache Tomcat patched 11 vulnerabilities affecting supported and end-of-life releases.- Apache Tomcat 9, 10.1 and 11 users are affected, along with end-of-life Tomcat 8.5.
- Affected versions include Tomcat 9.0.0.M1β9.0.120, 10.1.0-M1β10.1.57 and 11.0.0-M1β11.0.24.
- Important flaws enable security-constraint bypasses, RewriteValve access-control bypasses and fail-open principal lookups.
- An HTTP/2 allocation leak triggered by stream resets can cause denial of service.
- Other flaws affect SNI validation, DIGEST authentication, servlet roles, FORM authentication, WebSocket sessions and Unix socket permissions.
π Source: tomcat.apache.org Β· π Coverage: herodevs.com Β· π via Cyber Security News, cryptika.com (discovered)
π΅οΈ RESEARCH & DEEP DIVES
- Reported Log4j FOIS Bypass May Enable RCE in Narrow Setups
A reported Log4j deserialization bypass may enable RCE in narrowly configured applications.- Applications using Log4j serialized-event receivers are potentially affected.
- The reported flaw bypasses FilteredObjectInputStreamβs allowlist through java.rmi.MarshalledObject; no CVE is assigned.
- A crafted serialized LogEventProxy triggers MarshalledObject.get(), which deserializes the inner payload with an unfiltered ObjectInputStream.
- Reportedly affected versions include log4j-api 2.11.0β2.26.1 and log4j-core 2.8.0β2.26.1; exploitation requires a reachable receiver and a usable JVM gadget chain.
π Source: github.com Β· π Coverage: sonatype.com Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-80202 β CVSS 9.3 β Kimai before 2.56.0 Authorization Bypass via TimesheetVoterKimai before 2.56....
-
CVE-2026-80198 β CVSS 8.7 β Kimai before 2.56.0 Information Disclosure via config() Twig FunctionKimai ve...
-
CVE-2026-80197 β CVSS 8.7 β Kimai before 2.57.0 Improper Authorization via Favorite EndpointsKimai before...
-
CVE-2026-80196 β CVSS 8.7 β Kimai before 2.58.0 Authentication Bypass via Password Reset LinkKimai before...
-
CVE-2026-80195 β CVSS 8.7 β Kimai before 2.63.0 Team Membership Removal via APIKimai before 2.63.0 contai...
-
CVE-2026-80194 β CVSS 8.7 β Kimai before 2.64.0 Missing Authorization via ProjectViewController exportKim...
-
CVE-2026-80193 β CVSS 8.7 β Kimai before 2.62.0 Authorization Bypass via QuickEntryKimai before 2.62.0 fa...
-
CVE-2026-80191 β CVSS 8.7 β GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthen...
-
CVE-2026-80192 β CVSS 8.6 β better-auth SSO before 1.6.27 Domain Ownership Authentication Bypass@better-a...
-
CVE-2026-19398 β CVSS 6.8 β βunsupported-when-assigned.β An out-of-bounds write in the SmiFlash SMM modul...
-
CVE-2026-80199 β CVSS 6.3 β Kimai before 2.54.0 Username Enumeration via Timing OracleKimai before 2.54.0...