Kryptovaluta-ticker:
sysadmin fra Cyber Security News

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

Abinaya
Wednesday at 05:28
5 Visninger
0 Kommentarer
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known Exploited Vulnerabilities catalog. The agency said the vulnerability is being actively exploited and urged organizations to apply vendor mitigations before the August 7, 2026 deadline. CVE-2026-34486 is a missing encryption of sensitive data vulnerability in Apache Tomcat. It is categorized under CWE-311, which covers failures to protect sensitive information with encryption. The flaw allows attackers to bypass Tomcat’s EncryptInterceptor, a security component that encrypts communication in clustered Tomcat deployments. An incomplete fix for the earlier CVE-2026-29146...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!