The Apache Software Foundation has released Tomcat 11.0.26, an Apache Tomcat Update that resolves 12 security vulnerabilities. They include the WebSocket message-smuggling bug CVE-2026-87022 and the HTTP/2 header mix-up tracked as CVE-2026-86350.
First seen on thecyberexpress.com
Jump to article: thecyberexpress.com/apache-tomcat-update-cve-2026-87022/
![]()

