Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Apache Tomcat Vulnerability (CVE‑2026‑34486)

A high‑severity vulnerability (CVE-2026-34486) has been identified in Apache Tomcat’s EncryptInterceptor component. This flaw allows attackers to bypass encryption between cluster nodes, potentially exposing sensitive data in transit.
 
Affected Systems:
 
  • Apache Tomcat Software: versions 9.0.13 to 9.0.116, 10.1.0-M1 to 10.1.53 and 11.0.0-M1 to 11.0.20
 
Security Risks
 
Successful exploitation of this vulnerability could allow an attacker to bypass the EncryptInterceptor, resulting in sensitive data being transmitted without encryption between affected Apache Tomcat cluster nodes. This exposure increases the risk of information disclosure, interception of credentials, and manipulation of application data.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Apply the latest supported security updates for affected Apache Tomcat Software as soon as possible to address the vulnerabilities.
 
Upgrade to the following supported versions:
 
2. Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

11 August 2026

© 2026 National Cyber Security Authority