CVE-2026-34486: Apache Tomcat EncryptInterceptor Fail-Open Bypass
Technical analysis shows CVE-2026-34486 is a one-line fail-open regression in Tomcat Tribes enabling unauthenticated RCE via Java deserialization.
CVE-2026-34486 is a fail-open regression in Tomcat's Tribes EncryptInterceptor, introduced while fixing the CVE-2026-29146 padding-oracle flaw; Apache rated it Important and NVD scores it 7.5 High. Decryption failures are now forwarded to an unfiltered ObjectInputStream, and public PoC repositories demonstrate unauthenticated RCE on default port 4000 when clustering, the EncryptInterceptor, a reachable receiver and deserialization gadgets are all present. Affected releases 9.0.116, 10.1.53 and 11.0.20 are fixed in 9.0.117, 10.1.54 and 11.0.21; Tomcat 8.5 is unaffected.
Brazil orders Discord to suspend livestreaming after teen suicide
Brazil's data protection authority orders Discord to disable its Go Live livestreaming feature nationwide until child-safety safeguards are demonstrated.
Brazil's National Data Protection Authority (ANPD) found robust evidence that Discord failed to protect children from harmful content and ordered the Go Live feature suspended until effective safeguards are shown, following the July death of a 13-year-old girl during a roughly 45-minute livestream; five teenagers were arrested. Discord has three business days to implement the suspension and could face fines of up to 50 million reais (about $10 million) per violation. Regulators criticized the March addition of end-to-end encryption to Go Live for limiting real-time content detection, and are also investigating Discord's age-verification and content-removal practices, while a parallel probe tied neo-Nazi recruitment communities to Telegram.