www.cisa.gov 8/4/2026, 5:06:10 PM · external

CISA Adds Apache Tomcat Flaw CVE-2026-34486 to KEV Catalog

Developing story vulnerability 2 articles tracked
Apache Tomcat missing encryption flaw (CVE-2026-34486) added to CISA KEV catalog
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as a critical resource for the cybersecurity community, allowing organizations to effectively manage vulnerabilities and stay updated on actively exploited vulnerabilities. Key features include:

1. **CVE-2026-34486**: A significant vulnerability in Apache Tomcat involving missing encryption of sensitive data, allowing for potential bypass of security measures.

2. **Mitigation Guidance**: Organizations are urged to apply vendor mitigations and adhere to CISA guidance, including BOD 26-04 for prioritizing security updates based on risk.

3. **Reporting New Vulnerabilities**: Stakeholders can nominate new vulnerabilities for inclusion in the catalog if they are aware of any not currently listed.

4. **Formats Available**: The KEV catalog can be accessed and downloaded in CSV, JSON, and print formats to accommodate different user needs.

5. **Subscriptions**: Users can subscribe to updates for the latest vulnerabilities to stay informed.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline