Status: KEV | Advisory ID: CVE-2026-34486
| CVE | CVE-2026-34486 |
| Vulnerability Name | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | see table below |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-311 (Missing Encryption of Sensitive Data) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-08-04. |
| Exploitation prediction (EPSS) | 6.56% probability of exploitation in the next 30 days (94% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-08-07 (CISA KEV, Binding Operational Directive). |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Apache | Tomcat | ||
| Red Hat | Enterprise Linux | ||
| Red Hat | JBoss Web Server | ||
| Red Hat | Enterprise Linux Extended Life Cycle Support (ELS) | ||
| Red Hat | Enterprise Linux Extended Update Support (EUS) | ||
| Red Hat | Enterprise Linux Telco Update Service (TUS) | ||
| Red Hat | Enterprise Linux Update Services for SAP Solutions |
| Subsystems | EWS Workstation Delivery/Virtualization |
| Sectors | All Sectors |
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Monitor Apache's and Red Hat's web pages for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-34486 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-34486 |
| Field | Value |
|---|---|
| KEV Link | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| Date Added to KEV | 2026-08-04 |
| Required Action Due Date | 2026-08-07 |
| Required Action | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |