Insecure Default Configuration in Apache Tomcat Native
CVE-2026-86246
Currently unrated
What is CVE-2026-86246?
An insecure default configuration in Apache Tomcat Native exposes users to potential security risks by enabling vulnerable options by default. Specifically, options such as ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF, and ALLOW_NO_DHE_KEX can lead to compromised security. To mitigate these risks, users are strongly advised to upgrade to the latest secure versions: 2.0.16 or 1.3.9.
Affected Version(s)
Apache Tomcat Native 2.0.0 <= 2.0.15
Apache Tomcat Native 1.3.0 <= 1.3.8