Signal is active with 1 mentions in latest observed window
Immediate actions
Patch apache tomcat systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
🚨 CRITICAL - Tomcat FFM Connector CRL Validation Bypass (CVE-2026-53434)
Apache Tomcat has a CWE-390 flaw in its FFM-based TLS connector when certificate revocation lists (CRLs) are configured, where an error condition is detected but not properly acted upon. The root cause is improper error handling (detection of an error condition without enforcing failure), leading to incorrect revocation checking behavior. An attacker can exploit this over the network during TLS client-certificate authentication by presenting a certificate that should be rejected, relying on CRL processing errors being ignored or mishandled. Impact is authentication bypass and unauthorized access to CRL-protected endpoints, potentially enabling access to restricted applications and sensitive data.
👉 Affected: Apache Tomcat 11.0.0-M1–11.0.22, 10.1.0-M7–10.1.55, 9.0.83–9.0.118 | Upgrade to 11.0.23 / 10.1.56 / 9.0.119
Post summary
The post announces CVE-2026-53434, a CRL validation bypass flaw in Apache Tomcat’s FFM connector, details its technical aspects, and advises upgrading to patched versions.