ZeroHour
Web discovery (articles for new exploits & KEV entries)published ()ingested Pavel Buchnev2
Found by web discovery while looking for coverage of CVE-2026-34486

CVE-2026-34486: Apache Software Foundation Apache Tomcat

highExploit / PoC exploited in the wildimportance 72CVE-2026-34486CVE-2026-29146
AI summary · glm-5.3-flash

CISA added CVE-2026-34486, an actively exploited Apache Tomcat EncryptInterceptor bypass enabling unauthenticated deserialization RCE, to its KEV catalog.

CVE-2026-34486 allows bypass of Apache Tomcat's EncryptInterceptor, a flaw introduced by the fix for padding-oracle issue CVE-2026-29146 in Tribes cluster encryption. CISA added the flaw to the Known Exploited Vulnerability catalog on August 4, 2026, alongside actively exploited Langflow and N-central flaws, with remediation required under BOD 26-04 guidance. Official patches and workarounds are available, and reporting notes unauthenticated remote code execution through Java deserialization on the Tribes receiver port 4000.

  • Added to CISA KEV on August 4, 2026; exploitation is actively observed.
  • Fail-open regression from the CVE-2026-29146 fix exposes cluster traffic.
  • CISA's required action references BOD 26-04 mitigation guidance.
  • Reported alongside actively exploited Langflow and N-central vulnerabilities.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-34486
+1 in the same advisory: …29146
EncryptInterceptor Bypass Exposes Cluster Traffic in Apache Tomcat

CVE-2026-34486 is a missing-encryption vulnerability in Apache Tomcat in which the EncryptInterceptor, the component that encrypts Tomcat cluster communication, can be bypassed in a fail-open manner; the flaw was introduced as a regression by the fix for CVE-2026-29146. It affects Tomcat 11.0.20, 10.1.53 and 9.0.116, and is triggered when cluster communication is expected to be encrypted: an attacker positioned on the network path between cluster nodes receives inter-node traffic in cleartext. By reading that unencrypted traffic, the attacker can obtain sensitive data such as session payloads, potentially enabling session theft and authentication bypass as indicated by related reporting. Only deployments running the affected point releases with the EncryptInterceptor in use are impacted, including Tomcat shipped in Red Hat JBoss Web Server and Red Hat Enterprise Linux channels. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-04, EPSS places 30-day exploitation probability at 98.6%, though no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Upgrade Apache Tomcat to 11.0.21, 10.1.54 or 9.0.117, and apply the corresponding Red Hat JBoss Web Server / Enterprise Linux updates when published. Audit Tomcat cluster configurations for EncryptInterceptor usage, and until patched restrict or encrypt the network segment carrying inter-node cluster traffic. Because the flaw is in CISA's KEV catalog, federal agencies must patch per BOD 26-04 timelines and should review cluster nodes for signs of session data interception.

7.599% KEV
  • Apache Tomcat 11.0.20, 10.1.53, 9.0.116 (fixed in 11.0.21, 10.1.54, 9.0.117)
  • Red Hat JBoss Web Server (ships affected Tomcat)
  • Red Hat Enterprise Linux (including ELS, EUS, TUS, and Update Services for SAP Solutions)
largetens of thousands of Tomcat deployments on the affected point releases
Full article375 words · extracted from cve.tools · click to collapse

Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Published: Apr 9, 2026Updated: Aug 10, 2026

Sources: CVE List NVD BDU

CWE-311

Exploitability

CISA Known Exploited Vulnerability

Added to KEV:Aug 4, 2026

Remediation due:Aug 7, 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Official Patch Available

Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique

Collection

View detailed technique mapping

References

News mentions

5

Was this CVE page helpful?

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-34486 and every CVE in our database. Create a free account — no credit card required.

Create Free Account

Plain-language analysis

Impact assessment and exploitation scenario in plain English

Attack graph visualization

Interactive attack path and kill chain mapping

Exploit details & PoC links

ExploitDB, Metasploit, GitHub PoCs with direct links

Nuclei scanner templates

Ready-to-use vulnerability scanner templates

Full remediation guide

Patch instructions, workarounds, and compliance impact

Interactive AI chat

Ask questions about this vulnerability in natural language

Related vulnerabilities

Semantically similar CVEs and attack patterns

REST API & MCP access

Integrate vulnerability data into your workflows

Text extracted automatically; images, tables and formatting may be missing. Original: https://cve.tools/v/CVE-2026-34486