CVE-2026-86246: Apache Tomcat Native: Insecure OpenSSL options enabled
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOWCLIENTRENEGOTIATION, NOEXTENDEDMASTERSECRET, IGNOREUNEXPECTEDEOF and ALLOWNODHEKEX.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected.
Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcat Nativeto a version that resolves this vulnerability.Fixed in 2.0.16 - Upgrade
Upgrade
Apache Tomcat Nativeto a version that resolves this vulnerability.Fixed in 1.3.9
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8 are affected. Earlier unsupported versions may also be affected.
Are insecure TLS options enabled without administrator action?
Yes. The affected versions enable ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF, and ALLOW_NO_DHE_KEX by default during resource initialization.
What should teams do to remediate the issue?
Upgrade Apache Tomcat Native to version 2.0.16 or 1.3.9, which fix the issue.