CVE-2026-34486 · CVSS 7.5 HIGH · EPSS 7% · KEV 2026-08-04 · patch available
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Is CVE-2026-34486 exploited?
Listed in the CISA KEV catalog on 2026-08-04.
Federal remediation due 2026-08-07.
Past that date by 61 days.
EPSS puts exploitation in the next 30 days at 7%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
Apache · Tomcat · <11.0.19
Apache · Tomcat · Native <1.3.7
Apache · Tomcat · Native <2.0.14
Red Hat · JBoss Web Server · <6.2.3
Apache · Tomcat · <9.0.116
Apache · Tomcat · <9.0.117
Apache · Tomcat · <10.1.53
Apache · Tomcat · <11.0.20
Apache · Tomcat · <11.0.21
HCL · Commerce · 9.1.0-9.1.19.0
Apache · Tomcat · <10.1.52
Apache · Tomcat · <10.1.54
Is there a patch?
Tomcat 11.0.19
Tomcat Native 1.3.7
Tomcat Native 2.0.14
JBoss Web Server 6.2.3
Tomcat 9.0.116
Tomcat 9.0.117
Tomcat 10.1.53
Tomcat 11.0.20
Tomcat 11.0.21
Tomcat 10.1.52
Tomcat 10.1.54
What PlainSec published about CVE-2026-34486
PlainSec has not published a story about this CVE.