Kryptovaluta-ticker:
sysadmin fra Cyber Security News

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

Abinaya
Wednesday at 05:28
6 Visninger
0 Kommentarer
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known Exploited Vulnerabilities catalog. The agency said the vulnerability is being actively exploited and urged organizations to apply vendor mitigations before the August 7, 2026 deadline. CVE-2026-34486 is a missing encryption of sensitive data vulnerability in Apache Tomcat. It is categorized under CWE-311, which covers failures to protect sensitive information with encryption. The flaw allows attackers to bypass Tomcat’s EncryptInterceptor, a security component that encrypts communication in clustered Tomcat deployments. An incomplete fix for the earlier CVE-2026-29146...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!