Insecure Default Configuration in Apache Tomcat Native
CVE-2026-86246

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86246?

An insecure default configuration in Apache Tomcat Native exposes users to potential security risks by enabling vulnerable options by default. Specifically, options such as ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF, and ALLOW_NO_DHE_KEX can lead to compromised security. To mitigate these risks, users are strongly advised to upgrade to the latest secure versions: 2.0.16 or 1.3.9.

Affected Version(s)

Apache Tomcat Native 2.0.0 <= 2.0.15

Apache Tomcat Native 1.3.0 <= 1.3.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.