PT-2026-53742 · Apache+2 · Apache Tomcat+2

·

CVE-2026-53434

·

Published

2026-06-22

·

Updated

2026-09-11

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.22 Apache Tomcat versions 10.1.0-M7 through 10.1.55 Apache Tomcat versions 9.0.83 through 9.0.118
Description An issue exists in the FFM-based TLS connector when certificate revocation lists (CRLs) are configured. The software detects an error condition during CRL processing but fails to act upon it, leading to improper error handling. A remote attacker can exploit this during TLS client-certificate authentication by presenting a certificate that should be rejected. If the CRL configuration is invalid, the system ignores the error and may accept invalid certificates, potentially resulting in authentication bypass, unauthorized access to protected endpoints, or a denial of service.
Recommendations Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.22 to version 11.0.23. Upgrade Apache Tomcat versions 10.1.0-M7 through 10.1.55 to version 10.1.56. Upgrade Apache Tomcat versions 9.0.83 through 9.0.118 to version 9.0.119.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11857
BIT-TOMCAT-2026-53434
CVE-2026-53434
OESA-2026-2947
OESA-2026-2948
OESA-2026-2949
OESA-2026-2950
OPENSUSE-SU-2026:11195-1
OPENSUSE-SU-2026:11208-1
OPENSUSE-SU-2026:11209-1
OPENSUSE-SU-2026:21327-1
OPENSUSE-SU-2026:21328-1
OPENSUSE-SU-2026:21329-1
SUSE-SU-2026:22646-1
SUSE-SU-2026:22647-1
SUSE-SU-2026:22648-1
SUSE-SU-2026:3087-1
SUSE-SU-2026:3088-1
SUSE-SU-2026:3112-1
SUSE-SU-2026:3167-1

Affected Products

Apache Tomcat
Confluence
Red Os