Defensive self-check · CISA KEV 2026-08-04
Apache Tomcat CVE-2026-34486: version self-check
CISA added CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on 2026-08-04. Apache says the issue is a gap in the EncryptInterceptor on three specific builds. This page tells you which version to compare on a server you own. It does not describe how to exploit the issue.
Fixed versions
- 11.0.20 is fixed in 11.0.21.
- 10.1.53 is fixed in 10.1.54.
- 9.0.116 is fixed in 9.0.117.
- Apache lists only these three builds as affected.
Check these three things
- Version. Read the version from the Tomcat manager, the startup log, or
RELEASE-NOTESin the Tomcat directory. Compare it with the three builds above. - Where it faces. Note whether the HTTP port is reachable from the internet or only from an internal network.
- Accounts and files. Review administrator accounts and application files changed after 2026-08-04 that were not part of an upgrade you ran.
What to do
Upgrade to 11.0.21, 10.1.54, or 9.0.117 before you keep investigating. If the server was on one of the three affected builds, keep it on the fixed release and review the account and file lists above.
Vendor records: the Apache Tomcat announcement and the CISA KEV catalog, entry CVE-2026-34486.