Apache Tomcat Native: Client certificate requirements can be down-graded (CVE-2026-86247) | HOL Guard CVE