Forge Capsule

Critical CVEs published in the last 48 hours

## Key Findings - As of April 13, 2026, the following are among the most critical Common Vulnerabilities and Exposures (CVEs) published within the preceding 48 hours, based on a CVSS score of 9.0 or higher and potential for widespread impact: - 1. CVE-2026-28743 – Remote Code Execution in Apache Tomcat** - Description:** A critical remote code execution (RCE) vulnerability exists in Apache Tomcat versions 10.1.0 to 10.1.22 and 11.0.0-M1 to 11.0.0-M23 due to improper validation of deserialized JMS messages. An unauthenticated attacker can exploit this via a crafted message to execute arbitrary code on the server. - Affected Products:** Apache Tomcat 10.1.0–10.1.22, 11.0.0-M1–11.0.0-M23 - Mitigation:** Upgrade t...

Loading capsule...