Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On July 28, 2026, Oracle released important security fixes for Tomcat versions 9 and 10, addressing multiple vulnerabilities. Key issues include CVE-2026-24734, a certificate revocation bypass, and CVE-2026-29146, which exposes sensitive data due to a padding oracle vulnerability in the EncryptInter...
Two critical vulnerabilities have been identified in Apache Tomcat, CVE-2026-34486 and CVE-2026-29146. CVE-2026-34486 allows bypassing of the EncryptInterceptor due to missing encryption of sensitive data, affecting versions 11.0.20, 10.1.53, and 9.0.116. CVE-2026-29146 is a Padding Oracle vulnerabi...
Apache Tomcat has reported multiple vulnerabilities affecting versions 9.x, 10.x, and 11.x, including CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, and CVE-2026-53434. These vulnerabilities could allow remote attackers to bypass security restrictions, exploit replay attacks, and generate incomplet...