CVE-2026-34486

High7.5Published on April 9, 2026

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Aug 4, 2026
  • US federal agencies must remediate it by Aug 7, 2026 (BOD 22-01)
  • First attack observed 111 days after disclosure

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Source: CISA KEV · Sep 8, 2026 Aug 14, 2026 Aug 7, 2026 Aug 7, 2026 Aug 5, 2026 Aug 4, 2026

CVSS score7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness type (CWE)CWE-311, CWE-807
Vendorsredhat, apache

Affected products

VendorsProductVersions
apachetomcat9.0.116
redhatjboss web server7.0.0
redhatenterprise linux8.0
redhatenterprise linux els7.0
redhatenterprise linux eus10.0
redhatenterprise linux tus8.8
redhatenterprise linux update services for sap solutions8.8

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database