← Back to search

CVE-2026-86246

9.1 CRITICAL

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows attackers to manipulate SSL/TLS renegotiation and encryption settings, potentially leading to unauthorized access or data exposure.
Exploitability
Exploitation is moderately difficult as it requires specific SSL/TLS renegotiation conditions to be met, and the attacker must have network access to the target.
Blast radius
If exploited, the vulnerability could lead to data breaches or unauthorized access to sensitive information hosted on the affected Apache Tomcat Native version.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Apache Tomcat Native version 2.0.16 or 1.3.9, which address the issue.
ssltlstomcatencryptionnetwork

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-1188

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.