CVE-2026-86247: Apache Tomcat Native: Client certificate requirements can be down-graded
Apache Tomcat Native CVE-2026-86247 can downgrade client-certificate checks via a race condition.
Mark Thomas disclosed CVE-2026-86247, a moderate-severity race condition in Apache Tomcat Native. Versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8 are affected, and unsupported releases may be as well. In some configurations, the flaw can downgrade client-certificate verification requirements. The notice does not report observed exploitation.