CVE-2026-34486 · Critical · CISA KEV
Apache Tomcat Encryption Bypass (CVE-2026-34486) Actively Exploited
Threat Engine Auto-Feed · data current as of 2026-08-05
CVE-2026-34486 in Apache Tomcat, listed in CISA KEV, allows bypassing the EncryptInterceptor due to missing encryption of sensitive data. This vulnerability has a very high EPSS score (0.8116), indicating a high probability of exploitation, and is actively being exploited in the wild.
- CVSS:
- EPSS percentile: 0.99598
- Exploitation pressure: 85/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 100th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability stems from a failure to properly encrypt sensitive data within Apache Tomcat, specifically allowing an attacker to bypass the EncryptInterceptor. This means that data intended to be protected by encryption can be accessed or manipulated without the expected cryptographic safeguards.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using Apache Tomcat, especially those in financial services or technology sectors, are at heightened risk due to confirmed adversary targeting.
- Enterprises relying on Tomcat's EncryptInterceptor for data protection.
Misconfigurations that escalate it
- Any configuration where sensitive data is processed or stored by Apache Tomcat without additional layers of encryption or robust access controls.
- Inadequate monitoring for unusual access patterns to Tomcat instances or associated data stores.
High-impact scenarios
- An attacker could bypass encryption controls, leading to unauthorized access to sensitive data processed by Tomcat.
- Compromise of data confidentiality and integrity, potentially leading to regulatory non-compliance and reputational damage.
- Adversaries like FIN7, LockBit affiliates, APT38, APT29, and Scattered Spider are assessed to target sectors using Tomcat, indicating potential for financial theft, ransomware, or espionage.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor for any unusual activity or access attempts related to Apache Tomcat instances.
- Review logs for signs of EncryptInterceptor bypass attempts or unexpected data access.
- Implement robust network segmentation to limit the blast radius if a Tomcat instance is compromised.
Contain
- Isolate affected Apache Tomcat instances from the network immediately upon detection of compromise.
- Revoke any credentials or access tokens associated with potentially compromised Tomcat applications.
- Perform a forensic analysis to determine the extent of data exposure and attacker persistence.
Patch
- Apply the latest security patches and updates for Apache Tomcat as soon as they become available.
- Review and strengthen encryption configurations for all sensitive data handled by Tomcat, independent of the EncryptInterceptor.
Frontier verdict — Critical
Critical priority due to active exploitation (CISA KEV), high EPSS, and potential for sensitive data exposure in Apache Tomcat environments.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.