Skip to main content

Cybersecurity Weather

Global observatory

← Events

CVE-2026-34486

exploitation · critical · Evidence score 90

Vendor
Apache
Affected software
Apache Tomcat
Exploitation signal
Listed in CISA Known Exploited Vulnerabilities
EPSS
0.8116

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Provenance

  • CISA Known Exploited Vulnerabilities

    4 August 2026, 10:00 AM AEST

CVE-2026-34486 | Cyber Weather Index