CVE-2026-86246
9.1 CRITICALPublished 2026-09-23 · Updated 2026-09-23
AI risk analysis
- Summary
- The flaw allows attackers to manipulate SSL/TLS renegotiation and encryption settings, potentially leading to unauthorized access or data exposure.
- Exploitability
- Exploitation is moderately difficult as it requires specific SSL/TLS renegotiation conditions to be met, and the attacker must have network access to the target.
- Blast radius
- If exploited, the vulnerability could lead to data breaches or unauthorized access to sensitive information hosted on the affected Apache Tomcat Native version.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Apache Tomcat Native version 2.0.16 or 1.3.9, which address the issue.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-1188
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-18754
- CRITICALCVE-2026-93291
- CRITICALCVE-2017-20242
- CRITICALCVE-2026-0163
- CRITICALCVE-2026-101000PoC
- CRITICALCVE-2026-101038PoC
- CRITICALCVE-2026-101077PoC
- HIGHCVE-2026-11375
Related by shared AI tags and CWE weakness class. Browse the full archive.