OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-86243

HIGH · CVSS 7.5 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake can be exploited by a malicious user to cause a denial-of-service (DoS) by crashing the Java Virtual Machine (JVM). This issue impacts versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8, with earlier unsupported versions potentially affected as well. Organizations using affected versions should prioritize upgrading to versions 1.3.9 or 2.0.16 to mitigate this high-severity risk.

CVE
CVE-2026-86243
Severity
HIGH
CVSS
7.5
EPSS
0.60%
Apache

Original NVD Description

Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)