CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-73581, CVE-2026-75973, CVE-2026-76183 +12 more CVEs: tomcat native from 1.3.0 (inclusive), before 1.3.9 (exclusive), from 2.0.0 (inclusive), before…

CVE-2026-73581, CVE-2026-75973, CVE-2026-76183, CVE-2026-77756, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-86243, CVE-2026-86246, CVE-2026-86247, CVE-2026-86248, CVE-2026-86350, CVE-2026-87022 affects libtcnative-1-0. EPSS 0.00117 (percentile 0.01511), scored 2026-10-05. Fixed version: 1.3.9-160000.1.1. Fixed version: 2.0.16-160000.1.1. Fixed version: 9.0.122-160000.1.1. Fixed version: 10.1.60-160000.1.1. Fixed version: 11.0.26-160000.1.1. Fixed version: 1.3.9-160000.1.1. Fixed version: 2.0.16-160000.1.1. Fixed version: 9.0.122-160000.1.1.

CVE-2026-73581

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-75973

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-76183

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-77756

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-77762

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-77791

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-78383

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-78437

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-79677

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-86243

Affected technology

tomcat native · from 1.3.0 (inclusive), before 1.3.9 (exclusive)
apache

tomcat native · from 2.0.0 (inclusive), before 2.0.16 (exclusive)
apache

Apache Tomcat Native · 2.0.0 through 2.0.15, 1.3.0 through 1.3.8
Apache Software Foundation

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

A malicious user can trigger a DoS via a JVM crash. Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

CVE-2026-86246

Affected technology

tomcat native · from 1.3.0 (inclusive), before 1.3.9 (exclusive)
apache

tomcat native · from 2.0.0 (inclusive), before 2.0.16 (exclusive)
apache

Apache Tomcat Native · 2.0.0 through 2.0.15, 1.3.0 through 1.3.8
Apache Software Foundation

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-86247

Affected technology

tomcat native · from 1.3.0 (inclusive), before 1.3.9 (exclusive)
apache

tomcat native · from 2.0.0 (inclusive), before 2.0.16 (exclusive)
apache

Apache Tomcat Native · 2.0.0 through 2.0.15, 1.3.0 through 1.3.8
Apache Software Foundation

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-86248

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-86350

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-87022

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

Published

CVE
CVE-2026-77756, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-86243, CVE-2026-86246, CVE-2026-86247, CVE-2026-86248, CVE-2026-86350, CVE-2026-87022
CWE
CWE-126, CWE-366, CWE-1188
Product
libtcnative-1-0
CCR priority
0.0 /100 (P5)
EPSS
0.00117 · percentile 0.01511 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-73581.html