CVE-2026-65927

Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.


We have discovered 4,625 live websites that are affected by CVE-2026-65927.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains4,625 live websites (65% of Apache Tomcat install base)
Vulnerable Versions
  • from 8.5 through 8.5.100
  • from 9 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count231 versions ( 61% of all versions)


Common Weakness Enumeration

CWE-193 Off-by-one Error



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • 4ra1n, pyn3rd and unam4 (finder)

Website Distribution by Country

Number of websites using CVE-2026-65927
United States1,653 websites



China820 websites
Germany313 websites
France145 websites
Italy143 websites
Brazil93 websites
GB88 websites
Hong Kong86 websites
India81 websites

Website Distribution by TLD

Number of websites using CVE-2026-65927
.com1,956 websites
.de218 websites
.edu198 websites
.net184 websites
.cn180 websites
.org153 websites
.it132 websites
.com.br112 websites
.com.cn73 websites
.cz61 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65927

Top websites that are affected by CVE-2026-65927. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
See full domain list

FAQ

CVE-2026-65927 is Off-by-one Error in Apache Tomcat
A total of 4,625 websites have been identified as vulnerable to CVE-2026-65927, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-65927 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-65927.