← Back to Feed

Apache Tomcat Multiple Vulnerabilities

CVE-2026-34486

August 5, 2026 · HKCERT · Severity: HIGH

Multiple vulnerabilities were identified in Apache Tomcat that could allow a remote attacker to bypass security restrictions, disclose sensitive information, and manipulate data. CVE-2026-34486 is being actively exploited in the wild. Affected versions include Tomcat 9.0.13 to 9.0.116, 10.1.0-M1 to 10.1.53, and 11.0.0-M1 to 11.0.20.

Key Takeaways

  • Multiple vulnerabilities in Apache Tomcat allow security restriction bypass, information disclosure, and data manipulation.
  • CVE-2026-34486 is being actively exploited in the wild, affecting EncryptInterceptor.
  • Affected versions include Tomcat 9.0.13-9.0.116, 10.1.0-M1-10.1.53, and 11.0.0-M1-11.0.20.
☕ Buy a Coffee