Skip to main content
Question

Apache Tomcat Vulnerability CVE-2026-76183

  • October 1, 2026
  • 1 reply
  • 15 views

gemeentehw_mvk
Contributor
Forum|alt.badge.img+1

Hello,

Can someone tell me what impact the following Apache Tomcat vulnerability has on FME Flow 2026.2 build 26333?

CVE-2026-76183
https://lists.apache.org/thread.html/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp

Is it also possible to update only Apache Tomcat, or does the entire application need to be upgraded?

Thank you in advance.

1 reply

todd_davis
Influencer
Forum|alt.badge.img+23
  • Influencer
  • October 1, 2026

I would send Safe support this query.

2026.2 uses Tomcat 10.1.55, so it is using a vulnerable version, but that doesn’t mean that FME Flow is vulnerable

You can also upgrade Tomcat independently: https://support.safe.com/hc/en-us/articles/25407527726221-FME-Flow-Upgrade-Provide-Your-Own-Version-of-Tomcat

But I do have a question around whether you are using websockets and what authentications means you are using against that endpoint? I didn’t think websockets in FME Flow had this type of authentication??