The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known Exploited Vulnerabilities catalog. The agency said the vulnerability is being actively exploited and urged organizations to apply vendor mitigations before the August 7, 2026 deadline. CVE-2026-34486 is a missing encryption of sensitive data vulnerability in Apache Tomcat. It is categorized under CWE-311, which covers failures to protect sensitive information with encryption. The flaw allows attackers to bypass Tomcat’s EncryptInterceptor, a security component that encrypts communication in clustered Tomcat deployments. An incomplete fix for the earlier CVE-2026-29146...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!