< Back to all clusters
[TECHNOLOGY] · United States, Germany · 8 sources

started · updated

Apache Tomcat Vulnerability CVE-2026-34486 Actively Exploited, CISA Urges Immediate Patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed the Apache Tomcat encryption flaw CVE‑2026‑34486 in its Known Exploited Vulnerabilities catalog, stating that the vulnerability is being actively used in attacks. The flaw allows attackers to bypass the EncryptInterceptor component, exposing sensitive data in clustered Tomcat deployments. It affects Apache Tomcat versions 9.0.116, 10.1.53 and 11.0.20, with patches released in versions 9.0.117, 10.1.54 and 11.0.21.

Security researchers have observed a Chinese‑speaking threat actor exploiting the vulnerability, including attempts to deploy Java deserialization‑based reverse shells. CISA advises organizations to inventory all Tomcat instances—including cloud, container and internal deployments—and apply the vendor mitigations before the August 7 2026 deadline. Prompt patching is critical to prevent potential credential theft, lateral movement, data exfiltration or malware deployment.

Entities

Apache Software Foundation · Apache Tomcat · CVE-2026-34486 · Cybersecurity and Infrastructure Security Agency (CISA) · Unit 42