🗓️ WEBINAR | ft. Commvault : The Governance Gap — Why Policy Breaks Down at Scale Register Now 🗓️ WEBINAR | The Governance Gap — Why Policy Breaks Down at Scale

CyCognito Blog

Your source for exposure management research, product news, and security insights.

Search the Blog

By Igal Zeifman

An authentication bypass vulnerability in Apache Tomcat and Tomcat Native can allow unauthorized access to CLIENT_CERT-protected resources when OCSP soft-fail is disabled, bypassing the mutual TLS access control that the certificate validation policy was intended to enforce.

Read more about Emerging Threat: (CVE-2026-29145) Apache Tomcat CLIENT_CERT Authentication Bypass via OCSP Soft-Fail