[UPDATE] [medium] Apache Tomcat and Tomcat Native: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in Apache Tomcat to bypass security measures, manipulate data, disclose confidential information, conduct open redirect attacks, and carry out other unspecified attacks.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Apache Tomcat to bypass security measures, manipulate data, disclose confidential information, conduct open redirect attacks, and carry out other unspecified attacks.
- Who is affected
- Deployments of Apache Tomcat.
- Urgency
- Remediation is medium urgency due to the variety of potential attacks.
- Action
- Apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tomcat
Get an email when a new Tomcat advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1038
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-34486Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-248800.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-258540.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-291290.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-291450.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-291466.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-329900.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344830.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344870.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-345000.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34486 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-24880 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25854 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-29129 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-29145 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-29146 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-32990 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34483 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34500 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- unknownexploitedApache Tomcat Multiple Vulnerabilitieshkcert
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerabilitycisa-kev
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Jira: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25