# Apache Tomcat security vulnerabilities and exploitation

> Live situation record from CLSTR: https://clstr.news/situations/apache-tomcat-security-vulnerabilities-and-exploitation
> Updated: 2026-08-26T07:47:44.000Z. Sources: 3. Developments: 2.

Security concerns regarding Apache Tomcat have intensified following reports of active exploitation and the discovery of multiple vulnerabilities.

In early August 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified an encryption flaw, CVE-2026-34486, which allows attackers to bypass the EncryptInterceptor component. This vulnerability has been actively exploited by a Chinese-speaking threat actor to attempt the deployment of Java deserialization-based reverse shells. CISA urged organizations to patch affected versions of Apache Tomcat to prevent data exfiltration and credential theft.

Later in August, the Apache Software Foundation released version 11.0.25 to address a dozen additional security vulnerabilities. These include important flaws such as CVE-2026-65182 and CVE-2026-68569, which could allow attackers to bypass authentication methods like CLIENT-CERT and SPNEGO. Other disclosed issues involve an off-by-one error in the RewriteValve component, flaws in FORM-based authentication, and bugs that could lead to denial-of-service conditions.

By late August, the Apache Software Foundation released further patches addressing ten vulnerabilities in Apache Tomcat. These include important-rated flaws that could enable attackers to bypass security constraints or trigger denial-of-service conditions.

## Timeline

### 2026-08-26: Major software and hardware vulnerabilities disclosed across multiple platforms

A wave of critical security vulnerabilities has been disclosed affecting Apache Tomcat, WordPress plugins, DrayTek hardware, Drupal modules, and Red Hat software, risking unauthorized access and code execution.

3 sources. https://clstr.news/cluster/apache-tomcat-patches-dozen-security-vulnerabilities

### 2026-08-05: Apache Tomcat Vulnerability CVE-2026-34486 Actively Exploited, CISA Urges Immediate Patching

CISA warns that Apache Tomcat’s CVE‑2026‑34486 encryption flaw is being actively exploited; patches are available for affected versions and organizations should update immediately.

8 sources. https://clstr.news/cluster/apache-tomcat-vulnerability-cve-2026-34486-actively-exploited-cisa-urges-immediate-patching

---
Cite as: Apache Tomcat security vulnerabilities and exploitation. CLSTR, https://clstr.news/situations/apache-tomcat-security-vulnerabilities-and-exploitation
