Insecure Default Initialization of Resource in Apache Tomcat Native - CVE-2026-86246
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to weaken TLS connection security.
The vulnerability exists due to insecure default configuration in Apache Tomcat Native's OpenSSL option configuration when establishing TLS connections. A remote attacker can exploit the insecurely enabled OpenSSL options to weaken TLS connection security.