CVE-2026-86246

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-24: 309-24
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 Apache Tomcat Native'de CVSS 9.1'lik güvenlik açığı Apache Tomcat Native'de OpenSSL'in bazı güvensiz seçeneklerinin varsayılan olarak etkin olması nedeniyle CVE-2026-86246 yayınlandı. CVSS: 9.1 (Critical) Etkilenen: 1.3.0–1.3.8, 2.0.0–2.0.15 ✅ Çözüm / Yamalanan sürüm: 1.3.9 / 2.0.16 Advisory: https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol

    00030348
    2.4K followersView on X
  • ExploitGrid@exploitgrid

    🚨 CRITICAL | Apache Tomcat Native A security flaw, CVE-2026-86246, affects Apache Tomcat Native due to insecure OpenSSL options being enabled by default. 🔴 CVSS: 9.1 ⚠️ Affected: 1.3.0–1.3.8 & 2.0.0–2.0.15

    1000012
    47 followersView on X
  • ExploitGrid@exploitgrid

    💥 Insecure options include client renegotiation and unexpected EOF handling. ✅ Fixed: 1.3.9 & 2.0.16+ 🔗 CVE: CVE-2026-86246 🔗 Advisory: Apache Tomcat Native Security Advisory ⚠️ Using an affected version? Upgrade now. #ApacheTomcat #CVE #CyberSecurity #InfoSec

    0000010
    47 followersView on X

Explore more