Skip to main content

Cybersecurity Weather

Global observatory

← Vulnerabilities

CVE-2026-34486

EPSS 81%KEV

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Published
Last modified
CISA KEV
Yes
Ransomware use
Not indicated

Official sources

CVE-2026-34486 | Cyber Weather Index