| Audience: DocuShare Users and Administrators |
Apache Tomcat CVE-2026-65182, CVE-2026-65183, CVE-2026-65637, CVE-2026-65927, CVE-2026-65905, CVE-2026-66422, CVE-2026-68525, CVE-2026-68569, CVE-2026-68763 and Xerox DocuShare
| Summary: Xerox DocuShare evaluated nine Apache Tomcat security advisories against the standard DocuShare configuration. Based on this assessment, none of the nine vulnerabilities is exploitable in standard DocuShare deployments for DocuShare 7.5, 7.6, 7.7, 8.0, and 8.1. |
Overview
Xerox DocuShare evaluated the Apache Tomcat vulnerabilities listed below against the Tomcat configuration supplied with standard DocuShare deployments, including the released DocuShare 8.1 configuration. The assessment focuses on whether the vulnerable execution paths are available in the standard product configuration.
A vulnerability scanner may still identify a Tomcat version or package relationship in a standard deployment. A version-based scanner finding does not by itself establish that the vulnerable feature or execution path is enabled or reachable.
Security Advisories Reviewed
| Advisory | Assessment |
| CVE-2026-65182 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-65183 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-65637 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-65927 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-65905 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-66422 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-68525 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-68569 | Not exploitable in the standard DocuShare configuration. |
| CVE-2026-68763 | Not exploitable in the standard DocuShare configuration. |
Affected DocuShare Releases
| DocuShare release | Assessment |
| DocuShare 7.5 | Standard deployment not affected. |
| DocuShare 7.6 | Standard deployment not affected. |
| DocuShare 7.7 | Standard deployment not affected. |
| DocuShare 8.0 | Standard deployment not affected. |
| DocuShare 8.1 | Standard deployment not affected. |
Recommended Action
No corrective action is required for a standard DocuShare deployment based on this assessment. Continue to apply DocuShare maintenance releases and security updates according to the normal Xerox support and maintenance process.
- Do not disable DocuShare services or modify the bundled Tomcat configuration solely because one of these advisories is reported by a scanner.
- When documenting a scanner result, record the DocuShare release and determine whether the finding is based only on the detected Tomcat version or on an exploitable configuration.
- If your environment includes custom Tomcat connectors, web applications, valves, proxy settings, or other non-standard changes, contact Xerox DocuShare Support for a configuration-specific review.
| Important: This assessment applies to the standard Xerox DocuShare configuration. Custom Tomcat changes can alter the conditions under which a vulnerability is reachable and must be evaluated separately. |
How to Request Assistance
For questions about scanner finding, provide the CVE identifier, scanner evidence, DocuShare release, operating system, and any custom Tomcat configuration when contacting Xerox DocuShare Support.