CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
Severity: Moderate
Vendor: The Apache Software Foundation
Versions Affected:
Apache Tomcat Native 2.0.0 to 2.0.15
Apache Tomcat Native 1.3.0 to 1.3.8
Older, EOL versions may also be affected
Description:
Apache Tomcat Native enabled insecure options by default including
ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET,
IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX.
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat Native 2.0.16 or later
- Upgrade to Apache Tomcat Native 1.3.9 or later
History:
2026-09-23 Original advisory
References:
[1] https://tomcat.apache.org/security-native