RaqibCTI
CVE

CVE-2026-34486

P2
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache · Tomcat
Date added (CISA)
2026-08-04
Remediation due
2026-08-07
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16
  • DysphoriacampaignCorrelated cluster2026-08-24

Description

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Source: NVD ↗ · CISA KEV Catalog ↗