CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 4, 2026
- US federal agencies must remediate it by Aug 7, 2026 (BOD 22-01)
- First attack observed 111 days after disclosure
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Sep 8, 2026 Aug 14, 2026 Aug 7, 2026 Aug 7, 2026 Aug 5, 2026 Aug 4, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAffected products
| Vendors | Product | Versions |
|---|---|---|
| apache | tomcat | 9.0.116 |
| redhat | jboss web server | 7.0.0 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux els | 7.0 |
| redhat | enterprise linux eus | 10.0 |
| redhat | enterprise linux tus | 8.8 |
| redhat | enterprise linux update services for sap solutions | 8.8 |
Related articles
VulnerabilitiesCISA Adds Three Vulnerabilities to KEV Catalog: Langflow, Tomcat and N-central Affected
CISA adds three actively exploited vulnerabilities to the KEV catalog, impacting Langflow, Apache Tomcat, and N-central. Patch immediately by August 7, 2026.
VulnerabilitiesFortinet Fixes Critical Vulnerabilities in FortiWeb and FortiManager
Fortinet patches critical vulnerabilities in FortiWeb and FortiManager, including a CVSS 9.8 flaw allowing unauthorized admin access. Details and fixes.
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
APTSPECTRE, the backdoor that disables EDRs: inside UAT-10147's arsenal
Recently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
VulnerabilitiesSangoma Switchvox Under Attack: Critical SQL Injection Enables Remote Code Execution
CVE-2026-9586 in Sangoma Switchvox exploited via unauthenticated SQL injection at /pa enabling RCE. Update to 8.4.0.2 and hunt for compromise.
This product uses the NVD API but is not endorsed or certified by the NVD.