Apache Software FoundationCVE-2026-86246
Apache Tomcat Native: insecure default
Critical9.1CVE-2026-86246 · Published Sep 23, 2026 · updated Oct 6, 2026
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Tomcat Native Product | >= 2.0.0, <= 2.0.15 | No fix yet |
| >= 1.3.0, <= 1.3.8 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-1188
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Apache Tomcat Native: race condition | High7.4 | No fix yet |
| Sep 23 | Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake... | High7.5 | No fix yet |
| Sep 23 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat | Medium6.5 | No fix yet |
| Sep 23 | Apache Tomcat: authentication bypass | Critical9.8 | No fix yet |
| Sep 23 | Apache Tomcat: race condition | High8.1 | No fix yet |
| Sep 23 | Apache Sling XSS: cross-site scripting | Medium6.1 | 2.4.12 |