Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Goat Feed · Topic

    #apache

    Items tagged #apache

    Back to the daily feed
    criticalKEVBGC-RS 8.5Infra · likely in-scope

    CISA KEV: Apache Tomcat CVE-2026-34486 (CVSS 3.1 7.5 HIGH) - Tomcat Missing Encryption of Sensitive Data Vulnerability

    Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

    criticalKEVBGC-RS 4.2

    CISA KEV: Apache ActiveMQ CVE-2026-34197 - ActiveMQ Improper Input Validation Vulnerability

    Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.