Apache Tomcat Vulnerabilities Enables Bypass of EncryptInterceptor
ID: 9249a685-5798-5693-ba30-ef1b56d130e8
STIX ID: report--9249a685-5798-5693-ba30-ef1b56d130e8
Feed Name: cybersecurityNews.com
The Apache Software Foundation published emergency security updates for Apache Tomcat to address multiple vulnerabilities: a padding-oracle weakness in the EncryptInterceptor (CVE-2026-29146), a subsequent defective patch that permits an EncryptInterceptor bypass (CVE-2026-34486), and an OCSP certificate validation failure that can affect CLIENT_CERT authentication (CVE-2026-34500). Administrators are urged to upgrade affected branches immediately to Tomcat 11.0.21+, 10.1.54+, or 9.0.117+ to remediate decryption and authentication bypass risks across numerous 9.x, 10.x, and 11.x releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
