Apache Tomcat
Apache · current 11.0.25
The current version of Apache Tomcat is 11.0.25 (as of 12/08/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
8.1 high · over the network, without login · CISA deadline was 15 Apr 22
- CVE-2020-1938Apache Tomcat Improper Privilege Management Vulnerability
9.8 critical · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2016-8735Apache Tomcat Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 2 Jun 23
- CVE-2025-24813Apache Tomcat Path Equivalence Vulnerability
9.8 critical · over the network, without login · CISA deadline was 22 Apr 25
- CVE-2017-12617Apache Tomcat Remote Code Execution Vulnerability
8.1 high · over the network, without login · CISA deadline was 15 Apr 22
- CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
7.5 high · over the network, without login · CISA deadline was 7 Aug
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Apache Tomcat: Mehrere Schwachstellen
WID-SEC-W-2026-2123 · 18 Aug
- Apache Tomcat: Mehrere Schwachstellen
WID-SEC-W-2026-1514 · 12 Aug
- Apache Tomcat: Mehrere Schwachstellen
WID-SEC-W-2026-2310 · 6 Aug
- Apache Tomcat und Tomcat Native: Mehrere Schwachstellen
WID-SEC-W-2026-1038 · 5 Aug
- Apache Tomcat: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
WID-SEC-W-2026-2609 · 3 Aug
- Apache Tomcat: Schwachstelle ermöglicht Manipulation von Dateien
WID-SEC-W-2023-0460 · 3 Aug
- Apache Tomcat: Mehrere Schwachstellen
WID-SEC-W-2026-2610 · 3 Aug
- Apache Tomcat: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2026-2571 · 29 Jul
Apache Tomcat at a glance
Apache Tomcat is a widely used open-source Java servlet container and web server, hosting countless Java web applications. The project maintains several major branches in parallel with regular releases plus coordinated security fixes; as an often internet-facing application server, timely patching matters.
For admins the branch you run should stay on a supported line matched to your servlet/Java version — check that mapping before upgrades. Updates within a branch are usually low-risk (swap the release, restart), but sit them in a maintenance window. Tomcat has had notable security advisories (request handling, the AJP connector), so apply security releases promptly and disable connectors you don't use. Keep the manager app off the open network and behind strong authentication. Track the branch's end-of-life date; deployed web apps should be tested after larger jumps.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 11.0 | 11.0.25 | supported |
| 10.1 | 10.1.59 | supported |
| 10.0 | 10.0.27 | End of Life |
| 9.0 | 9.0.121 | EOL 31 Mar 27 |
| 8.5 | 8.5.100 | End of Life |
| 8.0 | 8.0.53 | End of Life |
| 7 | 7.0.109 | End of Life |
| 6 | 6.0.53 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 11.0.25 | STABLE | 12/08/2026 | – |
| 11.0.24 | STABLE | 03/07/2026 | – |
| 10.1.59 | STABLE | 13/08/2026 | – |
| 10.1.57 | STABLE | 03/07/2026 | – |
| 10.0.27 | STABLE | 03/10/2022 | – |
| 9.0.121 | STABLE | 12/08/2026 | – |
| 9.0.120 | STABLE | 03/07/2026 | – |
| 8.5.100 | STABLE | 19/03/2024 | – |
| 8.0.53 | STABLE | 29/06/2018 | – |
| 7.0.109 | STABLE | 22/04/2021 | – |
| 6.0.53 | STABLE | 02/04/2017 | – |
| 5.5.36 | STABLE | 10/10/2012 | – |
Frequently asked questions
- What is the latest version of Apache Tomcat?
- Apache Tomcat 11.0.25, released 12/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Apache Tomcat release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Apache Tomcat updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Apache Tomcat update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Apache TomcatEmbed this badge
Shows the current Apache Tomcat version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/tomcat)https://patchletter.com/badge/tomcat.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).