Get real-time updates on Telegram
CVE-2026-73581, CVE-2026-75973, CVE-2026-76183 +12 more CVEs: tomcat native from 1.3.0 (inclusive), before 1.3.9 (exclusive), from 2.0.0 (inclusive), before…
CVE-2026-73581, CVE-2026-75973, CVE-2026-76183, CVE-2026-77756, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-86243, CVE-2026-86246, CVE-2026-86247, CVE-2026-86248, CVE-2026-86350, CVE-2026-87022 affects libtcnative-1-0. EPSS 0.00117 (percentile 0.01511), scored 2026-10-05. Fixed version: 1.3.9-160000.1.1. Fixed version: 2.0.16-160000.1.1. Fixed version: 9.0.122-160000.1.1. Fixed version: 10.1.60-160000.1.1. Fixed version: 11.0.26-160000.1.1. Fixed version: 1.3.9-160000.1.1. Fixed version: 2.0.16-160000.1.1. Fixed version: 9.0.122-160000.1.1.
CVE-2026-73581
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-75973
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-76183
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-77756
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-77762
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-77791
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-78383
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-78437
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-79677
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-86243
Affected technology
tomcat native · from 1.3.0 (inclusive), before 1.3.9 (exclusive)
apache
tomcat native · from 2.0.0 (inclusive), before 2.0.16 (exclusive)
apache
Apache Tomcat Native · 2.0.0 through 2.0.15, 1.3.0 through 1.3.8
Apache Software Foundation
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
A malicious user can trigger a DoS via a JVM crash. Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.
CVE-2026-86246
Affected technology
tomcat native · from 1.3.0 (inclusive), before 1.3.9 (exclusive)
apache
tomcat native · from 2.0.0 (inclusive), before 2.0.16 (exclusive)
apache
Apache Tomcat Native · 2.0.0 through 2.0.15, 1.3.0 through 1.3.8
Apache Software Foundation
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-86247
Affected technology
tomcat native · from 1.3.0 (inclusive), before 1.3.9 (exclusive)
apache
tomcat native · from 2.0.0 (inclusive), before 2.0.16 (exclusive)
apache
Apache Tomcat Native · 2.0.0 through 2.0.15, 1.3.0 through 1.3.8
Apache Software Foundation
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-86248
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-86350
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-87022
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- CVE
- CVE-2026-77756, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-86243, CVE-2026-86246, CVE-2026-86247, CVE-2026-86248, CVE-2026-86350, CVE-2026-87022
- CWE
- CWE-126, CWE-366, CWE-1188
- Product
- libtcnative-1-0
- CCR priority
- 0.0 /100 (P5)
- EPSS
- 0.00117 · percentile 0.01511 · 2026-10-05
- KEV
- no
Provenance
- OSV.dev · Source record · observed 2026-10-06 17:58:42.508367+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-73581.html