Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-86246: Apache Tomcat Native allows insecure connection settings

CVE-2026-86246 · published 5 days ago
Summary

The native library used by Apache Tomcat on Debian is shipped with several security options turned on that weaken encrypted connections. This can let a network attacker intercept or tamper with data exchanged by web applications using Tomcat. Upgrade to Tomcat Native 2.0.16 or 1.3.9 (or later) to have these options disabled by default.

What to do
  • Update debian tomcat-native to version 2.0.16-1.
Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache tomcat native <= 2.0.15
Debian:12 debian tomcat-native All versions
Debian:14 debian tomcat-native < 2.0.16-1
Fix: upgrade to 2.0.16-1
Ubuntu:16.04:LTS canonical tomcat-native All versions
Original advisory text
DEBIAN-CVE-2026-86246
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published24 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta