CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
CLIENTCERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.
Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.26 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.60 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.122
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using CLIENT_CERT authentication with OCSP checking are affected when they run Apache Tomcat 11.0.0-M14 through 11.0.25, 10.1.22 through 10.1.59, or 9.0.92 through 9.0.121. The issue concerns scenarios where OCSP soft-fail is disabled.
What should be upgraded to remediate the issue?
Upgrade to Apache Tomcat 11.0.26, 10.1.60, or 9.0.122, as applicable to the release line in use. These versions fix the incomplete prior fix.
How can I determine whether an installation needs attention?
Check the deployed Tomcat version and whether CLIENT_CERT authentication and OCSP validation are enabled. Systems in the listed version ranges using this authentication configuration should be treated as affected.