Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities HKCERT

Apache Tomcat Multiple Vulnerabilities

Multiple vulnerabilities in Apache Tomcat, including CVE-2026-34486 (CVSS 7.5 HIGH), can lead to security restriction bypass, information disclosure, and data manipulation. The article notes CVE-2026-34486 is being actively exploited. Affected versions include Apache Tomcat 9.0.116, 10.1.53, and 11.0.20, with fixes available in versions 9.0.117, 10.1.54, and 11.0.21 respectively.
Read Full Article →

Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, sensitive information disclosure and data manipulation on the targeted system. Note: CVE-2026-34486 is being exploited in the wild. If EncryptInterceptor... Impact Security Restriction Bypass Information Disclosure Data Manipulation System / Technologies affected Apache Tomcat version 9.0.13 to 9.0.116 Apache Tomcat version 10.1.0-M1 to 10.1.53 Apache Tomcat version 11.0.0-M1 to 11.0.20 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.117 https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.54 https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.21

Share this article