CRITICAL
9.8 CVE-2026-86248 Published 23 Sept 2026
Apache Tomcat Client Certificate Authentication Bypass Vulnerability
Worried this affects your website?
Apache Tomcat contains a client certificate authentication bypass vulnerability in which CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled.
The issue affects the following versions:
- Apache Tomcat 11.0.0-M14 through 11.0.25
- Apache Tomcat 10.1.22 through 10.1.59
- Apache Tomcat 9.0.92 through 9.0.121
Users are recommended to upgrade to version 11.0.26, 10.1.60, or 9.0.122, which fix the issue.
Reference: CVE-2026-86248 on NVD
← Back to Security News