Buffer Over-read Vulnerability in Apache Tomcat Native Software
CVE-2026-86243

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86243?

A buffer over-read vulnerability exists in Apache Tomcat Native during the TLS handshake. This flaw allows hostile entities to exploit the system, potentially leading to a denial of service (DoS) through a Java Virtual Machine (JVM) crash. The affected versions range from 2.0.0 to 2.0.15 and 1.3.0 to 1.3.8, with earlier unsupported versions likely impacted as well. It is imperative for users to upgrade to version 1.3.9 or 2.0.16 where this issue is resolved.

Affected Version(s)

Apache Tomcat Native 2.0.0 <= 2.0.15

Apache Tomcat Native 1.3.0 <= 1.3.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.