logo

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

ID: 0c6ed09f-5d41-5254-9b87-d90d522afda7

STIX ID: report--0c6ed09f-5d41-5254-9b87-d90d522afda7

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Abinaya

ADMIRALTY:B6
...
...

CVE-2026-34486 is a high-severity Apache Tomcat EncryptInterceptor bypass affecting Tomcat 11.0.20, 10.1.53, and 9.0.116; CISA has added it to its Known Exploited Vulnerabilities catalog due to active exploitation. Unit 42 observed a Chinese-speaking actor using the flaw in an AI-assisted campaign to attempt Java deserialization reverse shells. Apache released patches (11.0.21, 10.1.54, 9.0.117); organizations are urged to identify exposed Tomcat instances, apply updates immediately, and restrict cluster communication as an interim mitigation while investigating for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.