CVE-2026-34486: Apache Software Foundation Apache Tomcat
CISA added CVE-2026-34486, an actively exploited Apache Tomcat EncryptInterceptor bypass enabling unauthenticated deserialization RCE, to its KEV catalog.
CVE-2026-34486 allows bypass of Apache Tomcat's EncryptInterceptor, a flaw introduced by the fix for padding-oracle issue CVE-2026-29146 in Tribes cluster encryption. CISA added the flaw to the Known Exploited Vulnerability catalog on August 4, 2026, alongside actively exploited Langflow and N-central flaws, with remediation required under BOD 26-04 guidance. Official patches and workarounds are available, and reporting notes unauthenticated remote code execution through Java deserialization on the Tribes receiver port 4000.
- Added to CISA KEV on August 4, 2026; exploitation is actively observed.
- Fail-open regression from the CVE-2026-29146 fix exposes cluster traffic.
- CISA's required action references BOD 26-04 mitigation guidance.
- Reported alongside actively exploited Langflow and N-central vulnerabilities.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-34486 +1 in the same advisory: …29146 | EncryptInterceptor Bypass Exposes Cluster Traffic in Apache Tomcat CVE-2026-34486 is a missing-encryption vulnerability in Apache Tomcat in which the EncryptInterceptor, the component that encrypts Tomcat cluster communication, can be bypassed in a fail-open manner; the flaw was introduced as a regression by the fix for CVE-2026-29146. It affects Tomcat 11.0.20, 10.1.53 and 9.0.116, and is triggered when cluster communication is expected to be encrypted: an attacker positioned on the network path between cluster nodes receives inter-node traffic in cleartext. By reading that unencrypted traffic, the attacker can obtain sensitive data such as session payloads, potentially enabling session theft and authentication bypass as indicated by related reporting. Only deployments running the affected point releases with the EncryptInterceptor in use are impacted, including Tomcat shipped in Red Hat JBoss Web Server and Red Hat Enterprise Linux channels. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-04, EPSS places 30-day exploitation probability at 98.6%, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Upgrade Apache Tomcat to 11.0.21, 10.1.54 or 9.0.117, and apply the corresponding Red Hat JBoss Web Server / Enterprise Linux updates when published. Audit Tomcat cluster configurations for EncryptInterceptor usage, and until patched restrict or encrypt the network segment carrying inter-node cluster traffic. Because the flaw is in CISA's KEV catalog, federal agencies must patch per BOD 26-04 timelines and should review cluster nodes for signs of session data interception. | 7.5 | 99% | KEV |
| largetens of thousands of Tomcat deployments on the affected point releases |
Full article375 words · extracted from cve.tools · click to collapse
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Exploitability
CISA Known Exploited Vulnerability
Added to KEV:Aug 4, 2026
Remediation due:Aug 7, 2026
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Official Patch Available
Workaround Available
Attack Graph
Products CVE Techniques Tactics
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 technique
Collection
References
News mentions
5
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
en-us·BleepingComputer·Aug 5, 2026
Exploited
Langflow ai-ml
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
en-us·SecurityWeek·Aug 5, 2026
Exploited
Langflow web-app
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
en·The Hacker News·Aug 5, 2026
Exploited
Langflow knaithe
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
en·The Hacker News·Jul 30, 2026
Roundup
xplogs22 phishing
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
en-us·Palo Alto Unit 42·Jul 30, 2026
PoC
Hermes Agent knaithe
Was this CVE page helpful?
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-34486 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
Text extracted automatically; images, tables and formatting may be missing. Original: https://cve.tools/v/CVE-2026-34486