CRITICAL 9.8 CVE-2026-86248 Published 23 Sept 2026

Apache Tomcat Client Certificate Authentication Bypass Vulnerability

Worried this affects your website?

Apache Tomcat contains a client certificate authentication bypass vulnerability in which CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled.

The issue affects the following versions:

  • Apache Tomcat 11.0.0-M14 through 11.0.25
  • Apache Tomcat 10.1.22 through 10.1.59
  • Apache Tomcat 9.0.92 through 9.0.121

Users are recommended to upgrade to version 11.0.26, 10.1.60, or 9.0.122, which fix the issue.

Reference: CVE-2026-86248 on NVD

← Back to Security News