Patch Matrix for CVE-2026-86350: Which Apache Tomcat Builds Need 11.0.26, 10.1.60 or 9.0.122
Operator summary
CVE-2026-86350 is an Important-severity Apache Tomcat defect involving a request header mix-up in HTTP/2 handling. It is a regression from the fix for CVE-2026-41293. Remediation is a version move, and the correct target depends on the branch a server runs.
Patch matrix
| Branch | Vulnerable range | Fixed release | Vendor commit |
|---|---|---|---|
| Tomcat 11.0.x | 11.0.22 to 11.0.25 | 11.0.26 | 192bc749 |
| Tomcat 10.1.x | 10.1.55 to 10.1.59 | 10.1.60 | 259e938d |
| Tomcat 9.0.x | 9.0.118 to 9.0.121 | 9.0.122 | 5adadc4e |
Tomcat 8.5 does not appear against this CVE on the vendor security pages. Older 11.0.x, 10.1.x and 9.0.x builds outside the listed ranges are not covered by the regression.
Why the ranges start where they do
The vulnerable code entered the tree with the CVE-2026-41293 fix, so the exposure window is bounded by that commit and the corrective commit in each branch. Because the ranges are contiguous and short, an inventory that records exact Tomcat build numbers can classify hosts immediately rather than by guesswork.
Severity and scoring
Apache labels the entry Important. The project does not publish a CVSS vector for it in the 11 security page. A third-party release roundup assigns 9.1 under CWE-444 to CVE-2026-86350; that number comes from the aggregator and should be treated as context, not as a vendor score.
Verification checklist
- Read the exact server version from the Tomcat startup log or from the manager application.
- Confirm whether any connector has HTTP/2 enabled, since the defect lives in HTTP/2 request interpretation.
- Check whether an upstream proxy or load balancer rewrites or pools HTTP/2 requests in front of Tomcat.
- Record the fix commit hash for the branch in use so change tickets can cite it.
Exposure snapshot
ZoomEye returns 580,597 results for app="Apache Tomcat" (about 580.6k assets), while vul.cve="CVE-2026-86350" returns 0. The gap is normal for a freshly published CVE and means the product count reflects the size of the exposed Tomcat base, not confirmed vulnerable instances.
Mitigation while change control runs
Disable HTTP/2 on the affected connector if the upgrade cannot be scheduled quickly. Log review for HTTP/2 requests with mismatched header expectations gives an early signal. Neither control replaces the patch, and both should be revisited once 11.0.26, 10.1.60 or 9.0.122 is deployed.
References
- Tomcat 11 security page: https://tomcat.apache.org/security-11.html
- Tomcat 10 security page: https://tomcat.apache.org/security-10.html
- Tomcat 9 security page: https://tomcat.apache.org/security-9.html
- Third-party roundup with the 9.1 figure: https://securityonline.info/apache-tomcat-vulnerabilities-11-0-26/
Top comments (0)