BlackTreeCVE IntelligenceSAP · 3763800
Linked CVE review
Assess and apply SAP security advisory 3763800
- Linked CVEs
- 3
- Confirmed exploited
- 0
- PoC or lab evidence
- 0
- Maximum CVSS
- 9.8
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2026-41293 Critical technical severity Apache Tomcat: HTTP/2 request headers not validatedImproper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue. | 9.8 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.68% · 76.2th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |
CVE-2026-43512 Critical technical severity Apache Tomcat: Digest authenticator will authenticate any unknown userDEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. | 9.8 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.33% · 70.1th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |
CVE-2026-43515 Critical technical severity Apache Tomcat: Security constraints not correctly appliedImproper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. | 9.1 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.22% · 67.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |