## Overview
CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities (KEV) list on August 4, 2026. This vulnerability affects Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116. The addition to the KEV list indicates a federal deadline for remediation due to evidence of exploitation.
## Technical Details
CVE-2026-34486 is a missing encryption of sensitive data vulnerability. It arises from a flaw in the EncryptInterceptor, which allows attackers to bypass encryption mechanisms. This vulnerability stems from a fix related to CVE-2026-29146, suggesting a regression in security measures. Attackers can exploit this flaw to access sensitive data that should be encrypted, posing a significant risk to affected systems.
## Impact
The vulnerability has a CVSS score of 7.5, indicating a high severity level. Successful exploitation could lead to unauthorized access to sensitive data, which can have severe repercussions for organizations relying on Apache Tomcat for their applications. The potential for data breaches makes this vulnerability critical to address promptly.
## Mitigation
Users of affected Apache Tomcat versions should upgrade immediately to version 11.0.21, 10.1.54, or 9.0.117. This upgrade addresses the vulnerability and restores the intended encryption functionality. Organizations should prioritize this update to protect against potential exploitation and safeguard sensitive data.
CSURFACE Threat Sensor