Saturday, September 19, 2026

Apache Tomcat Security Update for Remote Code Execution Vulnerability on Windows

Apache foundation has released security updates to address vulnerability with Apache Tomcat that allows a remote attacker to exploit the vulnerability and to take control over the vulnerable machine.

The vulnerability exists in the CGI Servlet, due to the way it passes the JRE command line arguments to the windows when running on with enableCmdLineArguments enabled.

Apache fixed the vulnerability by disabling the CGI option enableCmdLineArguments by default. This vulnerability can be tracked as
CVE-2019-0232.

The bug was identified and reported to the Apache foundation by an external security researcher through the bug bounty program.

Affected versions

Apache Tomcat 9.0.0.M1 to 9.0.17
Apache Tomcat 8.5.0 to 8.5.39
Apache Tomcat 7.0.0 to 7.0.93

Mitigations

Apache recommends users to update with the following versions and to ensure CGI Servlet initialization parameter enableCmdLineArguments is set to false.

Upgrade to Apache Tomcat 9.0.18 or later when released
Upgrade to Apache Tomcat 8.5.40 or later when released
Upgrade to Apache Tomcat 7.0.93 or later when released

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Apache Software Foundation Releases Important Security Patches for Multiple Apache Tomcat Versions

A Flaw in Apache HTTP Server Allows any Users to Gain Root Access

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet

Google has confirmed that its Gemini artificial intelligence model...

AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes

Researchers have identified a new Android banking Trojan called...

PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner

A sophisticated cryptomining campaign is employing multiple layers of...

PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains

China-aligned threat actors are using low-quality Chinese-language casino and...

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Feral Wolf has expanded its ransomware tradecraft by abusing...

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

A newly observed ransomware operation dubbed SETTRA is abusing...

JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data

JADEPUFFER, the agentic threat actor first linked to an...

Related Articles

Recent News