All incidents

Apache Tomcat missing encryption flaw (CVE-2026-34486) added to CISA KEV catalog

vulnerabilityopenAug 4, 2026 — Aug 4, 2026

THE US Cybersecurity and Infrastructure Security Agency has added CVE‑2026‑34486 to its Known Exploited Vulnerabilities catalogue, warning that a missing encryption flaw in Apache Tomcat can be exploited remotely without authentication.

The vulnerability scores 7.5 on the CVSS v3.1 scale and resides in the EncryptInterceptor component, which is responsible for encrypting sensitive data within Tomcat.

Because the EncryptInterceptor fails to encrypt certain data, an attacker can circumvent its protections and obtain or alter information that should remain confidential, all without needing valid credentials.

CISA noted that active exploitation of this flaw has been observed in the wild, prompting its inclusion in the KEV catalogue, although no specific threat actors have been publicly linked to the attacks.

Administrators should apply the patch released by Apache as soon as possible, follow CISA’s binding operational directive BOD 26‑04 for prioritising security updates, and review EncryptInterceptor configurations to ensure the component is correctly enabled.

Organisations are also advised to test the update in a non‑production environment before deployment, monitor logs for unexpected access to the EncryptInterceptor, and consider restricting network exposure of Tomcat instances until the fix is verified.

Intelligence briefing updated Aug 4, 2026

CVE-2026-34486 7.5 KEV
Root sourcenvd.nist.gov
Timeline Coverage

Swipe to explore timeline