CISA added CVE-2026-34486, a high-severity flaw that lets attackers bypass Apache Tomcat's EncryptInterceptor and read sensitive cluster traffic, to its Known Exploited Vulnerabilities catalog on August 4, 2026.
What Is It
CVE-2026-34486 is a Missing Encryption of Sensitive Data vulnerability (CWE-311) in Apache Tomcat, introduced by the fix for CVE-2026-29146. The regression allows the EncryptInterceptor, the component responsible for encrypting Tomcat cluster communication, to be bypassed, leaving data that administrators believe is encrypted exposed instead.
NVD rates it 7.5 HIGH with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N: network-reachable, low complexity, no privileges and no user interaction required, with high confidentiality impact and no impact to integrity or availability.
Why It Matters
CISA's inclusion of this CVE in the KEV catalog confirms active exploitation in the wild. The attack requires no authentication and no user interaction over the network, and the confidentiality-only impact profile fits data exposure rather than takeover. Known ransomware campaign use is listed as Unknown.
The KEV due date is August 7, 2026: three days after the entry was added, an unusually tight remediation window.
What's Vulnerable
Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 are affected.
Downstream Red Hat products are also in scope, including Red Hat Enterprise Linux 7 ELS, 8, 9, and 10 (plus EUS, TUS, and E4S/SAP Solutions variants) and Red Hat JBoss Web Server 7.0.
Patch Status
Apache recommends upgrading to 11.0.21, 10.1.54, or 9.0.117. Red Hat has shipped fixed packages via errata RHSA-2026:36787 through RHSA-2026:39188.
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Sources
- CISA Known Exploited Vulnerabilities Catalog; entry added 2026-08-04
- Apache security advisory; https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
- NVD, https://nvd.nist.gov/vuln/detail/CVE-2026-34486
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- Red Hat errata; https://access.redhat.com/errata/RHSA-2026:36787