Legacy Core
Official Guidance

CISA adds Apache Tomcat vulnerability to the KEV Catalog

CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.

Official source
Cybersecurity and Infrastructure Security Agency
Jurisdiction
United States
Publication date
August 4, 2026
Legacy Core review
August 17, 2026 · Christopher Green
Source checked
August 17, 2026
Affected sectors
Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
Deadline date
August 7, 2026

Summary

CISA added CVE-2026-34486, an Apache Tomcat missing-encryption vulnerability that can bypass EncryptInterceptor and be chained with CVE-2025-24813, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. The catalog due date of August 7, 2026 applies to federal agencies, not to private businesses.

Why it matters

Tomcat is background software that some practice-management and business applications run on, so a firm can depend on it without using the name day to day. Catalog inclusion does not mean a particular system is affected.

Recommended action

Ask your IT owner, managed service provider, or practice-software vendor whether any of your systems run Apache Tomcat and whether the vendor mitigation has been applied. Keep the response with your security-maintenance records.

CISA adds Apache Tomcat vulnerability to the KEV Catalog — Legacy Core Intelligence | Legacy Core