CVE-2026-86247: Apache Tomcat Native
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.
Affected products
- Apache Tomcat Native: from 1.3.0, before 1.3.9 (fixed in 1.3.9); from 2.0.0, before 2.0.16 (fixed in 2.0.16)
Published 2026-09-23. Last modified 2026-10-06.