PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated May 14, 2026

Apache Tomcat Tribes EncryptInterceptor Bypass - Remote Code Execution

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-34486
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Tomcatby Apache Software Foundation
11.0.20
Red Hat Enterprise Linux 10by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 10by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Enterprise Linux 10.0 Extended Update Supportby Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.