{"id":11913,"date":"2026-04-14T19:19:48","date_gmt":"2026-04-15T01:19:48","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/"},"modified":"2026-09-29T08:39:36","modified_gmt":"2026-09-29T14:39:36","slug":"alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/","title":{"rendered":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected Product(s):<\/h2>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected Versions<\/strong><\/td><\/tr><tr><td><strong>Apache Tomcat 9<\/strong><\/td><td>9.0.13 \u2013 9.0.116<\/td><\/tr><tr><td><strong>Apache Tomcat 10<\/strong><\/td><td>10.1.0 \u2013 10.1.53<\/td><\/tr><tr><td><strong>Apache Tomcat 11<\/strong><\/td><td>11.0.0 \u2013 11.0.20<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 &#8211; Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions.<\/p>\n\n<p class=\"wp-block-paragraph\">The main vulnerabilities are detailed below:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE-2026-34486 (CVSS 9.1 &#8211; Critical)<\/strong>: EncryptInterceptor bypass; an attacker manipulates requests to evade encryption completely. Specifically affects 9.0.116, 10.1.53, and 11.0.20.<\/li>\n\n\n\n<li><strong>CVE-2026-29146 (CVSS 7.5 &#8211; High)<\/strong>: Padding Oracle in EncryptInterceptor allows decrypting sensitive data via adaptive attacks. Covers from 9.0.13 to 9.0.116 (9.x), 10.1.0-M1 to 10.1.53 (10.x), 11.0.0-M1 to 11.0.20 (11.x).<\/li>\n\n\n\n<li><strong>CVE-2026-34487 (CVSS 7.5 &#8211; High)<\/strong>: is a vulnerability of type <strong>insertion of sensitive information into log files (CWE-532)<\/strong> in the <em>cloud membership for clustering<\/em> component of Apache Tomcat.   When Tomcat is deployed in a Kubernetes cluster and uses this component for cluster member discovery, the code <strong>logs the bearer token of the Kubernetes service account<\/strong> it uses to talk to the cluster API. That <strong>Kubernetes bearer token<\/strong> should be treated as a secret (equivalent to a service credential), but ends up written to files like catalina.out or the configured application logs.<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE-2026-29145 (CVSS 9.1 \u2013 Critical)<\/strong>: It is a vulnerability in Apache Tomcat and Tomcat Native where, under certain scenarios, <strong>CLIENT_CERT<\/strong> authentication does not fail as it should when the <em>soft fail<\/em> option is disabled, allowing <strong>invalid or revoked<\/strong> client certificates to be accepted and gain access to resources that should be protected by mutual TLS authentication.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">These vulnerabilities allow remote code execution (RCE), privilege escalation, and credential theft in production environments. Versions 9.0.116, 10.1.53, and 11.0.20 fixed CVE-2026-29146, but introduced CVE-2026-34486, so it is recommended to immediately update to versions 9.0.117, 10.1.54, or 11.0.21 (or higher).<\/p>\n\n<p class=\"wp-block-paragraph\">Given the high level of exposure in cloud environments and Kubernetes deployments, it is recommended to prioritize update tasks on all Apache Tomcat web servers exposed to the Internet.<\/p>\n\n<h2 class=\"wp-block-heading\">Solution:<\/h2>\n\n<p class=\"wp-block-paragraph\">The recommended solution is to update Apache Tomcat to the versions that fix these vulnerabilities: 9.0.117, 10.1.54, or 11.0.21 (or higher), depending on the installed branch.<\/p>\n\n<p class=\"wp-block-paragraph\">These versions already include fixes for the encryption issues, token leaks, and authentication bypass, and are available for direct download from the official Apache Tomcat project website, on the download pages for each branch:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Branch 9.0 <a href=\"https:\/\/tomcat.apache.org\/download-90.cgi\">https:\/\/tomcat.apache.org\/download-90.cgi<\/a><\/li>\n\n\n\n<li>Branch 10.0 <a href=\"https:\/\/tomcat.apache.org\/download-10.cgi\">https:\/\/tomcat.apache.org\/download-10.cgi<\/a><\/li>\n\n\n\n<li>Branch 11.0 https:\/\/tomcat.apache.org\/download-11.cgi<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/tomcat.apache.org\/security.html\">https:\/\/tomcat.apache.org\/security.html<\/a><\/li>\n\n\n\n<li>https:\/\/securityonline.info\/apache-tomcat-security-vulnerabilities-encryption-bypass-token-leak\/<\/li>\n<\/ul>\n","protected":false},"featured_media":10457,"template":"","class_list":["post-11913","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"5000\" \/>\n\t\t<meta property=\"og:image:height\" content=\"2715\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-15T01:19:48+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T14:39:36+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#listItem\",\"name\":\"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/\",\"name\":\"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab\",\"description\":\"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/Apache_Tomcat_Logo.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#mainImage\",\"width\":5000,\"height\":2715},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\\\/#mainImage\"},\"datePublished\":\"2026-04-14T19:19:48-06:00\",\"dateModified\":\"2026-09-29T08:39:36-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab","description":"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#listItem","name":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#listItem","position":2,"name":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/","name":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab","description":"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#mainImage","width":5000,"height":2715},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/#mainImage"},"datePublished":"2026-04-14T19:19:48-06:00","dateModified":"2026-09-29T08:39:36-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab","og:description":"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png","og:image:width":5000,"og:image:height":2715,"article:published_time":"2026-04-15T01:19:48+00:00","article:modified_time":"2026-09-29T14:39:36+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s - Beacon Lab","twitter:description":"Affected Product(s): Description Multiple critical vulnerabilities have been reported in Apache Tomcat, highlighting CVE-2026-34486 (CVSS 9.1 - Critical) which allows complete encryption bypass, along with CVE-2026-29146 (High) and CVE-2026-34487 (Kubernetes token leak). These affect exposed Tomcat servers and have been recently patched following a defective fix in intermediate versions. The main vulnerabilities are detailed below:","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png"},"aioseo_meta_data":{"post_id":"11913","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 14:38:39","updated":"2026-09-29 15:16:38","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-35 Critical Vulnerabilities in Apache Tomcat and one of them affects K8s","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11913\/revisions"}],"predecessor-version":[{"id":11914,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11913\/revisions\/11914"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/10457"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=11913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}