CISA adds Apache Tomcat vulnerability to the KEV Catalog
CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.
- Official source
- Cybersecurity and Infrastructure Security Agency ↗
- Jurisdiction
- United States
- Publication date
- August 4, 2026
- Legacy Core review
- August 17, 2026 · Christopher Green
- Source checked
- August 17, 2026
- Affected sectors
- Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
- Deadline date
- August 7, 2026
Summary
CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.
Why it matters
Tomcat is background software that some practice-management and business applications run on, so a firm can depend on it without using the name day to day. Catalog inclusion does not mean a particular system is affected.
Recommended action
Ask your IT owner, managed service provider, or practice-software vendor whether any of your systems run Apache Tomcat and whether the vendor mitigation has been applied. Keep the response with your security-maintenance records.