FR
live
Critical Actively exploited

CVE-2026-34486

Apache Tomcat

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

What this means

Likelihood
Exploitation is not hypothetical: CISA has observed it in the wild.

What to doTop priority: CISA sets the remediation deadline at 7 August 2026.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
4 August 2026
CVSS
EPSS
98.62% probability of exploitation within 30 days · above 100% of all CVEs
Weakness
CWE-311
CISA due date
7 August 2026 past due
Sources
cisa-kev
References

Type at least two characters.

navigate open esc dismiss