Apache Tomcat Multiple Vulnerabilities
Details
Original advisory: https://www.hkcert.org/security-bulletin/apache-tomcat-multiple-vulnerabilities_20260805
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2026-3448642.6% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 99% of all scored CVEs.
- Moderate exploitation riskCVE-2026-291466.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all scored CVEs.
- Low exploitation riskCVE-2026-344830.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-344870.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-345000.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34486 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-29146 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34483 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34500 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [medium] Apache Tomcat and Tomcat Native: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerabilitycisa-kev
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere Schwachstellencert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Siebel CRM: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Retail Applications: Multiple vulnerabilitiescert-bund
More from HKCERT Security Bulletins
- unknownTP-Link Omada Products Multiple Vulnerabilities2026-08-05
- unknownMozilla Firefox Information Disclosure Vulnerability2026-08-05
- unknownSUSE Linux Kernel Multiple Vulnerabilities2026-08-04
- unknownMicrosoft Edge Multiple Vulnerabilities2026-08-03
- unknownRedHat Linux Kernel Multiple Vulnerabilities2026-08-03