PT-2026-97311 · Apache · Tomcat Native

CVE-2026-86247

·

Published

2026-09-23

·

Updated

2026-09-30

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat Native versions 2.0.0 through 2.0.15 Apache Tomcat Native versions 1.3.0 through 1.3.8
Description A race condition within a thread allows client certificate verification requirements to be down-graded in certain configurations.
Recommendations Upgrade to version 2.0.16. Upgrade to version 1.3.9.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86247
OPENSUSE-SU-2026:11898-1
OPENSUSE-SU-2026:11899-1
OPENSUSE-SU-2026:21984-1
SUSE-SU-2026:23985-1

Affected Products

Tomcat Native