OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77762

HIGH · CVSS 8.1 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A race condition vulnerability in Apache Tomcat allows attackers to inject trailer fields into HTTP/2 requests, potentially leading to unauthorized data manipulation or exposure. This issue impacts multiple versions of Tomcat, including those that are currently supported and some that are end-of-life. Organizations using affected versions should prioritize upgrading to the latest patched releases to mitigate the risk.

CVE
CVE-2026-77762
Severity
HIGH
CVSS
8.1
EPSS
0.36%
Apache

Original NVD Description

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fix the issue.