← Back to Feed
Apache Tomcat Multiple Vulnerabilities
CVE-2026-34486
August 5, 2026 · HKCERT · Severity: HIGH
Multiple vulnerabilities were identified in Apache Tomcat that could allow a remote attacker to bypass security restrictions, disclose sensitive information, and manipulate data. CVE-2026-34486 is being actively exploited in the wild. Affected versions include Tomcat 9.0.13 to 9.0.116, 10.1.0-M1 to 10.1.53, and 11.0.0-M1 to 11.0.20.
Key Takeaways
- Multiple vulnerabilities in Apache Tomcat allow security restriction bypass, information disclosure, and data manipulation.
- CVE-2026-34486 is being actively exploited in the wild, affecting EncryptInterceptor.
- Affected versions include Tomcat 9.0.13-9.0.116, 10.1.0-M1-10.1.53, and 11.0.0-M1-11.0.20.