CVE-2026-34486
EPSS 81%KEV
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
- Published
- —
- Last modified
- —
- CISA KEV
- Yes
- Ransomware use
- Not indicated