Race Condition Vulnerability in Apache Tomcat Native
CVE-2026-86247

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86247?

The Apache Tomcat Native server has a race condition vulnerability that affects client certificate verification, allowing configuration downgrades in specific setups. This flaw compromises the integrity of secure connections. Users are advised to update to versions 2.0.16 or 1.3.9 to mitigate this risk, as unsupported versions may also be susceptible.

Affected Version(s)

Apache Tomcat Native 2.0.0 <= 2.0.15

Apache Tomcat Native 1.3.0 <= 1.3.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.