CVE-2026-34486
exploitation · critical · Evidence score 90
- Vendor
- Apache
- Affected software
- Apache Tomcat
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.8116
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Provenance
CISA Known Exploited Vulnerabilities
4 August 2026, 10:00 AM AEST