logo

CVE-2026-59084: Apache Tomcat EncryptInterceptor Misconfiguration Risk (CVSS 9.1)

ID: 324700db-0d09-5c63-ad4d-bb06b42dd46f

STIX ID: report--324700db-0d09-5c63-ad4d-bb06b42dd46f

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

...
...

**CVE-2026-59084 (Apache Tomcat EncryptInterceptor):** A critical (CVSS 9.1) vulnerability caused by insufficient documentation of EncryptInterceptor configuration that can leave Tomcat cluster replication traffic inadequately encrypted; an attacker on the cluster network could intercept, modify, or replay session replication data leading to session hijacking. The advisory lists affected versions, available patches, immediate remediation steps (update, review configuration, generate secure keys, and network isolation), and detection/post-remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.