Actively exploited
Listed in CISA’s Known Exploited Vulnerabilities catalog since August 4, 2026.
CVE-2026-34486
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Added to KEV August 4, 2026
Alert details
- Source feed
- CISA KEV
- CVE ID
- CVE-2026-34486
- CWE
- CWE-311
- Affected products
- Tomcat · Apache Tomcat · Apache
What happened
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
What it means for your business
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA due date: August 7, 2026
Sources
Related briefs
Windows PowerShell Remote Code Execution vulnerability
Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-8037). Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. CISA remediation due date: 2026-08-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Active Directory Elevation of Privilege vulnerability
Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Service Bus Remote Code Execution vulnerability
Azure Service Bus Remote Code Execution vulnerability (CVE-2026-50515) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.