Apache Tomcat

Apache · current 11.0.27

Are you Apache? Claim this page

The current version of Apache Tomcat is 11.0.27 (as of 06/10/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2017-12615Apache Tomcat on Windows Remote Code Execution VulnerabilityRansomware

    8.1 high · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2020-1938Apache Tomcat Improper Privilege Management Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2016-8735Apache Tomcat Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 2 Jun 23

  • CVE-2025-24813Apache Tomcat Path Equivalence Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 22 Apr 25

  • CVE-2017-12617Apache Tomcat Remote Code Execution Vulnerability

    8.1 high · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    7.5 high · over the network, without login · CISA deadline was 7 Aug

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Apache Tomcat at a glance

Apache Tomcat is a widely used open-source Java servlet container and web server, hosting countless Java web applications. The project maintains several major branches in parallel with regular releases plus coordinated security fixes; as an often internet-facing application server, timely patching matters.

For admins the branch you run should stay on a supported line matched to your servlet/Java version — check that mapping before upgrades. Updates within a branch are usually low-risk (swap the release, restart), but sit them in a maintenance window. Tomcat has had notable security advisories (request handling, the AJP connector), so apply security releases promptly and disable connectors you don't use. Keep the manager app off the open network and behind strong authentication. Track the branch's end-of-life date; deployed web apps should be tested after larger jumps.

Support cycles (endoflife.date)

CycleLatest versionStatus
11.011.0.27supported
10.110.1.61supported
10.010.0.27End of Life
9.09.0.123EOL 31 Mar 27
8.58.5.100End of Life
8.08.0.53End of Life
77.0.109End of Life
66.0.53End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
11.0.27STABLE06/10/2026–
11.0.26STABLE09/09/2026–
11.0.25STABLE12/08/2026–
11.0.24STABLE03/07/2026–
10.1.61STABLE06/10/2026–
10.1.60STABLE09/09/2026–
10.1.59STABLE13/08/2026–
10.1.57STABLE03/07/2026–
10.0.27STABLE03/10/2022–
9.0.123STABLE06/10/2026–
9.0.122STABLE10/09/2026–
9.0.121STABLE12/08/2026–
9.0.120STABLE03/07/2026–
8.5.100STABLE19/03/2024–
8.0.53STABLE29/06/2018–
7.0.109STABLE22/04/2021–
6.0.53STABLE02/04/2017–
5.5.36STABLE10/10/2012–

Frequently asked questions

What is the latest version of Apache Tomcat?
Apache Tomcat 11.0.27, released 06/10/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Apache Tomcat release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Apache Tomcat updates?
Tick Apache Tomcat off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Apache Tomcat version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Apache Tomcat version and keeps it up to date. Anyone may embed it, no account needed.

Apache Tomcat badge
[![Apache Tomcat](https://patchletter.com/badge/tomcat.svg)](https://patchletter.com/en/software/tomcat)
https://patchletter.com/badge/tomcat.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Servers & Databases