• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-34486: missing encryption in Apache Tomcat

Attackers can remotely bypass Tomcat’s EncryptInterceptor to obtain sensitive information from vulnerable Apache Tomcat servers (CVE-2026-34486). The flaw affects Tomcat releases 11.0.20, 10.1.53, and 9.0.116. Exploitation requires only network access; no valid account or user interaction is needed. Because encryption controls can be circumvented, confidential data that Tomcat is expected to protect may be disclosed to unauthorised parties until a vendor remediation is applied or effective mitigations are put in place.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.5HIGH
EPSS
0.06561
CWE
CWE-311
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this CVE to its KEV catalog with a remediation deadline for federal agencies and public exploit code exists—treat exposed Tomcat servers as high priority and apply mitigations immediately.

What is CVE-2026-34486?

Attackers can remotely bypass Tomcat’s EncryptInterceptor to obtain sensitive information from vulnerable Apache Tomcat servers (CVE-2026-34486). The flaw affects Tomcat releases 11.0.20, 10.1.53, and 9.0.116. Exploitation requires only network access; no valid account or user interaction is needed. Because encryption controls can be circumvented, confidential data that Tomcat is expected to protect may be disclosed to unauthorised parties until a vendor remediation is applied or effective mitigations are put in place.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Which versions of Apache Tomcat are affected?

BRANCHAFFECTEDFIXED
11.x11.0.20
10.x10.1.53
9.x9.0.116

Is CVE-2026-34486 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-04; US federal agencies must address it by 2026-08-07. Public exploit code is available.

How to fix CVE-2026-34486

  1. Implement the vendor's recommended mitigations immediately and watch Apache Tomcat advisories for a released fix.
  2. Restrict network access to Tomcat services using firewalls, network segmentation, and IP allowlists for management interfaces.
  3. Increase logging and monitor for indicators of exploit activity and unexpected data access.
  4. Follow CISA KEV guidance and document mitigation actions to meet BOD 26-04 requirements.

Frequently asked questions

Is CVE-2026-34486 being actively exploited?

CISA added CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on 2026-08-04 and required mitigations by 2026-08-07; public exploit code is available.

Which Tomcat versions are affected by CVE-2026-34486?

The affected Apache Tomcat versions are 11.0.20, 10.1.53, and 9.0.116.

Is there a patch for CVE-2026-34486?

As of 2026-09-29 no fixed releases are listed in the provided affected data; follow Apache Tomcat advisories for when a patch is issued and apply vendor guidance in the meantime.

Does CVE-2026-34486 require authentication?

No; the vulnerability can be exploited remotely without authentication or user interaction against affected Apache Tomcat instances.

References