logo

Apache Tomcat Vulnerability Enables Bypass of EncryptInterceptor Protection

ID: 9c0c2454-6e38-54a6-92f9-6be983e7c1c4

STIX ID: report--9c0c2454-6e38-54a6-92f9-6be983e7c1c4

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-04-13

Date Updated: 2026-04-13

Author: AnuPriya

...
...

Apache Tomcat released urgent security updates for three serious vulnerabilities: CVE-2026-29146 (EncryptInterceptor CBC/padding-oracle exposure), CVE-2026-34486 (a follow-up patch introduced a bypass of EncryptInterceptor), and CVE-2026-34500 (OCSP client certificate validation failures in certain configurations). The flaws affect multiple Tomcat 9, 10, and 11 branches, may allow decryption or unauthorized access, and Apache recommends immediate upgrade to the fixed releases while administrators should verify certificate validation and monitor session activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.