← All CVEs

CVE-2026-34486

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added 2026-08-04Remediation due 2026-08-07

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

7.5
CVSS
98.6%
EPSS (exploit prob.)
100th
EPSS percentile
2026-04-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-311CWE-807

Affected products

VendorProductAffected versions
apachetomcat9.0.116
apachetomcat10.1.53
apachetomcat11.0.20
redhatjboss_web_server7.0.0
redhatenterprise_linux8.0
redhatenterprise_linux9.0
redhatenterprise_linux10.0
redhatenterprise_linux_els7.0
redhatenterprise_linux_eus10.0
redhatenterprise_linux_tus8.8
redhatenterprise_linux_update_services_for_sap_solutions8.8
redhatenterprise_linux_update_services_for_sap_solutions9.2
redhatenterprise_linux_update_services_for_sap_solutions9.4
redhatenterprise_linux_update_services_for_sap_solutions9.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-34486