https://seclists.org/oss-sec/2026/q3/907: CVE-2026-86248: Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Published Sep 23, 2026
·Updated
Affected Software
1 affected component
Apache Tomcat>=11.0.0-M14<=11.0.25, >=10.1.22<=10.1.59, >=9.0.92<=9.0.121