CISA has added CVE-2026-34486 to its Known Exploited Vulnerabilities catalogue. Affected vendor: Apache, product: Tomcat. Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
The flaw is a missing encryption of sensitive data issue in Tomcat's EncryptInterceptor, enabling an attacker to circumvent encryption protections. The vulnerability resides in the EncryptInterceptor component, which is responsible for encrypting sensitive data within Tomcat. It can be exploited remotely without authentication, leading to potential disclosure or manipulation of protected data. CVSS v3.1 score is 7.5 (High). A patch is available from Apache.
CISA notes that active exploitation of this vulnerability has been observed, which is why it was added to the KEV catalogue. No public reports link this flaw to ransomware campaigns at this time. Federal civilian executive branch (FCEB) agencies must apply mitigations by the remediation due date of 7 August 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines.
Organisations should consult the Apache security thread at https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly for mitigation details. While the directive binds FCEB agencies, all organisations should review their exposure to Apache Tomcat and apply the patch or mitigations promptly.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-34486 and the CISA KEV catalogue.