DIRAS TAKE
Urgent: CISA added this CVE to its KEV catalog with a remediation deadline for federal agencies and public exploit code exists—treat exposed Tomcat servers as high priority and apply mitigations immediately.
What is CVE-2026-34486?
Attackers can remotely bypass Tomcat’s EncryptInterceptor to obtain sensitive information from vulnerable Apache Tomcat servers (CVE-2026-34486). The flaw affects Tomcat releases 11.0.20, 10.1.53, and 9.0.116. Exploitation requires only network access; no valid account or user interaction is needed. Because encryption controls can be circumvented, confidential data that Tomcat is expected to protect may be disclosed to unauthorised parties until a vendor remediation is applied or effective mitigations are put in place.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Which versions of Apache Tomcat are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.0.20 | |
| 10.x | 10.1.53 | |
| 9.x | 9.0.116 |
Is CVE-2026-34486 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-04; US federal agencies must address it by 2026-08-07. Public exploit code is available.
How to fix CVE-2026-34486
- Implement the vendor's recommended mitigations immediately and watch Apache Tomcat advisories for a released fix.
- Restrict network access to Tomcat services using firewalls, network segmentation, and IP allowlists for management interfaces.
- Increase logging and monitor for indicators of exploit activity and unexpected data access.
- Follow CISA KEV guidance and document mitigation actions to meet BOD 26-04 requirements.
Frequently asked questions
Is CVE-2026-34486 being actively exploited?
CISA added CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on 2026-08-04 and required mitigations by 2026-08-07; public exploit code is available.
Which Tomcat versions are affected by CVE-2026-34486?
The affected Apache Tomcat versions are 11.0.20, 10.1.53, and 9.0.116.
Is there a patch for CVE-2026-34486?
As of 2026-09-29 no fixed releases are listed in the provided affected data; follow Apache Tomcat advisories for when a patch is issued and apply vendor guidance in the meantime.
Does CVE-2026-34486 require authentication?
No; the vulnerability can be exploited remotely without authentication or user interaction against affected Apache Tomcat instances.
References
- nvd.nist.gov/vuln/detail/CVE-2026-34486
- cve.org/CVERecord?id=CVE-2026-34486
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486
- lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
- All Apache CVEs on CVE Radar
- CVEs published in September 2026