[KEV] CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Active exploitation (KEV)
What to do
- On CISA KEV — actively exploited. Patch immediately.
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
CVE · detail
- CVE-2026-34486KEVEPSS 99%NVD ↗