CISA adds CVE-2026-34486 to KEV catalog
CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in Apache Tomcat. The agency also added two other exploited flaws, including CVE-2026-9198 in Langflow, and gave US civilian federal agencies until Aug. 7 to remediate them.
CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a vulnerability in Apache Tomcat. The same update added two other actively exploited flaws, including CVE-2026-9198 in Langflow, and set a remediation deadline of 2026-08-07 for U.S. civilian federal agencies.
What does CVE-2026-34486’s inclusion in KEV mean?
CISA’s listing marks CVE-2026-34486 as a known, actively exploited vulnerability tied to Apache Tomcat. In KEV trackers, the flaw also appears as part of the set of weaknesses already being used in attacks.
f4n6 also reported that the updated SSVC status for CVE-2026-34486 now reflects active exploitation and full technical impact. That same report says the vulnerability affects only Tomcat 11.0.20, 10.1.53 and 9.0.116, with fixes in 11.0.21, 10.1.54 and 9.0.117.
The f4n6 reference also mentions public proof-of-concept activity for CVE-2026-34486, a detail that reinforces the view that attackers are operationalizing the issue. The entry available in NVD and KEV trackers matches the Apache Tomcat association.
What other vulnerability did CISA add to the same list?
CISA added CVE-2026-9198 to the catalog alongside CVE-2026-34486, and KEV trackers list it as a known, actively exploited vulnerability tied to IBM Langflow OSS. Including both flaws in the same update confirms the agency saw real exploitation activity in more than one product exposed in corporate environments.
The move leaves U.S. civilian federal agencies with a remediation window that closes on August 7 for the cases covered in this report. For organizations that manage exposed infrastructure, the KEV update serves as an immediate priority signal for public-facing or internet-accessible systems.
Sources
- CVE-2026-34486 — Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting itctipilot.ch· CTI Pilot
- CVE-2026-34486 Apache Tomcat - f4n6f4n6.co.uk· f4n6
- CVE-2026-34486 Detail - NVDnvd.nist.gov· NVD
- CISA KEV — Live Tablechangeriskintel.com· Change Risk Intel
- CISA KEV Catalog — Known Exploited Vulnerabilities Trackercvetodo.com· CVETodo
- CISA Añade Tres Vulnerabilidades Activamente Explotadascybersecurefox.com· Cybersecurefox



