Apache Tomcat vulnerabilities: known CVEs & security history
Apache · Web / Runtime · 37 tracked CVEs · 6 actively exploited · updated September 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Apache Tomcat release lines — 37 in total, with 6 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Apache Tomcat's current status and the safe version to run.
Known Apache Tomcat CVEs
Actively-exploited and most-severe first. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2020-1938⚡ exploited | critical | 9.8 | 99% | 2020 |
| CVE-2016-8735⚡ exploited | critical | 9.8 | 90% | 2017 |
| CVE-2017-12617⚡ exploited | high | 8.1 | 100% | 2017 |
| CVE-2017-12615⚡ exploited | high | 8.1 | 100% | 2017 |
| CVE-2026-34486⚡ exploited | high | 7.5 | 81% | 2026 |
| CVE-2023-44487⚡ exploited | high | 7.5 | 100% | 2023 |
| CVE-2026-65905 | critical | 9.8 | 1% | 2026 |
| CVE-2026-65637 | critical | 9.8 | 1% | 2026 |
| CVE-2026-68525 | critical | 9.1 | 1% | 2026 |
| CVE-2026-65182 | critical | 9.1 | 0% | 2026 |
| CVE-2026-59084 | critical | 9.1 | 0% | 2026 |
| CVE-2026-59083 | critical | 9.1 | 0% | 2026 |
| CVE-2026-55276 | critical | 9.1 | 0% | 2026 |
| CVE-2026-53434 | critical | 9.1 | 0% | 2026 |
| CVE-2022-25762 | high | 8.6 | 8% | 2022 |
| CVE-2026-68569 | high | 8.1 | 0% | 2026 |
| CVE-2026-66422 | high | 8.1 | 0% | 2026 |
| CVE-2026-65183 | high | 8.1 | 0% | 2026 |
| CVE-2026-68763 | high | 7.5 | 1% | 2026 |
| CVE-2026-65927 | high | 7.5 | 1% | 2026 |
| CVE-2026-29146 | high | 7.5 | 6% | 2026 |
| CVE-2026-24734 | high | 7.5 | 0% | 2026 |
| CVE-2021-25122 | high | 7.5 | 18% | 2021 |
| CVE-2020-13935 | high | 7.5 | 87% | 2020 |
| CVE-2020-13934 | high | 7.5 | 64% | 2020 |
| CVE-2026-55957 | high | 7.3 | 0% | 2026 |
| CVE-2026-53404 | high | 7.3 | 0% | 2026 |
| CVE-2021-25329 | high | 7 | 9% | 2021 |
| CVE-2020-9484 | high | 7 | 57% | 2020 |
| CVE-2026-73180 | medium | 6.8 | 0% | 2026 |
| CVE-2026-55956 | medium | 6.5 | 0% | 2026 |
| CVE-2026-55955 | medium | 6.5 | 0% | 2026 |
| CVE-2026-50229 | medium | 6.1 | 0% | 2026 |
| CVE-2021-24122 | medium | 5.9 | 23% | 2021 |
| CVE-2026-66299 | medium | 5.3 | 0% | 2026 |
| CVE-2021-33037 | medium | 5.3 | 75% | 2021 |
| CVE-2019-17569 | medium | 4.8 | 9% | 2020 |
Is my Apache Tomcat version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Apache Tomcat version → · Monitor Apache Tomcat for new CVEs →
Apache Tomcat vulnerabilities — frequently asked
How many known vulnerabilities does Apache Tomcat have?
IsItPatched tracks 37 CVEs for Apache Tomcat, 6 of which are actively exploited (CISA KEV). 10 are critical-severity and 19 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Apache Tomcat have any actively-exploited vulnerabilities?
Yes — 6 Apache Tomcat CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (1 linked to ransomware). Patch these as a priority.
What is the most severe Apache Tomcat vulnerability?
Among tracked issues, CVE-2020-1938 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest.
Is Apache Tomcat safe to use?
It depends on the version. The latest supported Apache Tomcat release (11.0.25) clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Apache Tomcat security status · Apache Tomcat end-of-life · actively-exploited CVEs. Always verify against Apache's advisories — see our disclaimer.