CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
ID: 0c6ed09f-5d41-5254-9b87-d90d522afda7
STIX ID: report--0c6ed09f-5d41-5254-9b87-d90d522afda7
Feed Name: cybersecurityNews.com
CVE-2026-34486 is a high-severity Apache Tomcat EncryptInterceptor bypass affecting Tomcat 11.0.20, 10.1.53, and 9.0.116; CISA has added it to its Known Exploited Vulnerabilities catalog due to active exploitation. Unit 42 observed a Chinese-speaking actor using the flaw in an AI-assisted campaign to attempt Java deserialization reverse shells. Apache released patches (11.0.21, 10.1.54, 9.0.117); organizations are urged to identify exposed Tomcat instances, apply updates immediately, and restrict cluster communication as an interim mitigation while investigating for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
