Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-86246: Apache Tomcat Native allows insecure connection settings
CVE-2026-86246 · published 5 days ago
Summary
The native library used by Apache Tomcat on Debian is shipped with several security options turned on that weaken encrypted connections. This can let a network attacker intercept or tamper with data exchanged by web applications using Tomcat. Upgrade to Tomcat Native 2.0.16 or 1.3.9 (or later) to have these options disabled by default.
What to do
- Update debian tomcat-native to version 2.0.16-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache tomcat native | <= 2.0.15 |
| Debian:12 | debian | tomcat-native | All versions |
| Debian:14 | debian | tomcat-native |
< 2.0.16-1 Fix: upgrade to 2.0.16-1
|
| Ubuntu:16.04:LTS | canonical | tomcat-native | All versions |
Original advisory text
DEBIAN-CVE-2026-86246
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
References
- https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/09/23/32 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-86246 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-86246 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-86246 Third Party Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published24 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-86246 · NVD
CVE-2026-86246 · MITRE
DEBIAN-CVE-2026-86246 · OSV
UBUNTU-CVE-2026-86246 · OSV
Track software like this
Free during beta