CVE-2026-29146Disclosure(apache / tomcat)

HIGHCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache tomcat systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209CWE-642CWE-1240

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 11 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 10d ago at 2 mentions (2026-04-09); latest day: 1
  • 12 total mentions across 11 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline12 mentions / 11d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-20: 1Mentions · 2026-04-24: 1Mentions · 2026-05-14: 1Mentions · 2026-07-04: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Mentions · 2026-08-07: 1Mentions · 2026-08-12: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-05-14: 1Exploit Tool / Code · 2026-07-04: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-12: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-14: 1Technical Details · 2026-04-20: 1Technical Details · 2026-05-14: 1Technical Details · 2026-07-04: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-12: 104-0904-1404-1504-2004-2405-1407-0408-0508-0608-0708-12
Signal classification5 categories
Disclosure
541.7%
Active Exploitation
325.0%
General
216.7%
Exploit
18.3%
PoC
18.3%
Referenced assets36 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-141
Disclosure1
2026-04-151
General1
2026-04-201
Disclosure1
2026-04-241
General1
2026-05-141
Exploit1
2026-07-041
PoC1
2026-08-051
Active Exploitation1
2026-08-061
Disclosure1
2026-08-071
Active Exploitation1
2026-08-121
Active Exploitation1
Full discourse12 posts
  • kmkz@kmkz_security
    PoC

    Fun story: #Apache patched a Tomcat padding oracle and shipped a worse bug doing it. #CVE-2026-29146: EncryptInterceptor defaults to AES/CBC/PKCS5, a padding oracle. No key needed, forge cluster messages on the Tribes receiver (TCP/4000, no peer auth) and you're a trusted node. > The patch moved super.messageReceived() out of the try. Then? Decrypt fails, Tomcat deserializes your bytes anyway: badab00m! That's CVE-2026-34486, pre-auth RCE! Patch to be safe, pwn for the lulz 😎 > Fix: 9.0.117 / 10.1.54 / 11.0.21. Or GCM/NoPadding and keep 4000 off untrusted wires. Whole story & details by @cyberkendra : https://www.cyberkendra.com/2026/04/apache-tomcats-security-fix-opened-door.html PoC from @striga_ai : http://github.com/striga-ai/CVE-2026-34486

    Post summary

    Apache Tomcat was found to have a padding oracle (CVE-2026-29146) and a pre‑auth RCE (CVE-2026-34486) with available patches, a PoC in GitHub, but no evidence of live exploitation is reported.

    013067305.4K
    19.8K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-34486: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor EncryptInterceptor Bypass Enables Plaintext Credential Exfiltration A regression introduced in the fix for CVE-2026-29146 inadvertently disabled proper enforcement of the EncryptInterceptor, allowing sensitive session data (e.g., authentication tokens, credentials) to be transmitted unencrypted over insecure channels despite configuration intent. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-34486 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-34486" Search Dork: app="Apache Tomcat" Exposure: 562.9k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgVG9tY2F0Ig==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260414 #Tomcat #EncryptionBypass #CVE-2026-34486 #SessionSecurity #CryptoMisconfiguration #DarkEye

    Post summary

    The tweet announces a new CVE (CVE‑2026‑34486) for Apache Tomcat, detailing a regression‑induced EncryptInterceptor bypass that can leak credentials, but provides no PoC, exploit, or patch information.

    0602396.9K
    12.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/04追加) #vulnerability 🛡CVE-2026-9198 IBM Langflow Code Injection Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / IBM Corporation (CNA) ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H IBM Langflow OSS 1.0.0 から 1.10.0 に存在するコードインジェクションの脆弱性です。 未認証の攻撃者が /api/v1/auto_login で SUPERUSER トークンを取得し、/api/v1/validate/code で任意コードを実行することで、既定構成の Langflow 環境でリモートコード実行に至る可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・IBM Langflow OSS 1.0.0 から 1.10.0 を使用している ・/api/v1/auto_login がネットワーク経由で到達可能である ・/api/v1/validate/code がネットワーク経由で到達可能である ・既定構成で auto-login 機能が有効である ・Langflow OSS 1.10.1 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者に SUPERUSER トークンを取得される可能性がある ・Langflow のコード検証機能を悪用される可能性がある ・対象ホスト上で任意の Python コードを実行される可能性がある ・APIキー、環境変数、外部連携先の認証情報を窃取される可能性がある ・Langflow 環境を起点に追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-9198 ・https://www.ibm.com/support/pages/node/7278927 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9198.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198 ・https://jvndb.jvn.jp/ja/cwe/CWE-94.html 🛡CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / N-able (CNA) ・種別:代替パスまたはチャネルを使用した認証回避 (CWE-288) ・CVSS:CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N N-able N-central に存在する、代替パスまたはチャネルを使用した認証回避の脆弱性です。 N-central 2026.1 までのバージョンが影響を受け、認証バイパスにつながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・N-able N-central 2026.1 以前を使用している ・攻撃者が N-central サーバーへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・N-central 2026.3.1.7 以降へ更新されていない ・関連する修正済みホットフィックスが適用されていない ✅悪用時影響 ・認証をバイパスされる可能性がある ・N-central サーバーへの管理アクセス取得につながる可能性がある ・管理対象エンドポイントへ到達される可能性がある ・Take Control 機能などを悪用される可能性がある ・Cloudflare Tunnel などを用いた永続化に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(N-able) ・概要:N-able は、2026年7月31日に Adlumin MDR が顧客環境で不審な活動を検知し、N-central サーバーのゼロデイ悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-18556 ・https://www.n-able.com/blog/n-central-security-update-august-4-2026 ・https://uptime.n-able.com/ ・https://github.com/cisagov/vulnrichment/blob/develop/2026/18xxx/CVE-2026-18556.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556 ・https://jvndb.jvn.jp/ja/cwe/CWE-288.html 🛡CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / CISA-ADP ・種別:重要なデータの暗号化の欠如 (CWE-311) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Apache Tomcat の EncryptInterceptor に存在する、重要なデータの暗号化の欠如に関する脆弱性です。 CVE-2026-29146 の修正に起因して EncryptInterceptor のバイパスが可能となり、機密データが暗号化されない可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:部分的 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・Apache Tomcat 11.0.20、10.1.53、または 9.0.116 を使用している ・Tomcat クラスタリング等で EncryptInterceptor を使用している ・攻撃者が EncryptInterceptor により保護される通信経路へ影響を及ぼせる ・Apache Tomcat 11.0.21、10.1.54、または 9.0.117 以降へ更新されていない ・CVE-2026-29146 の修正を含む影響バージョンを利用している ✅悪用時影響 ・EncryptInterceptor による暗号化をバイパスされる可能性がある ・本来暗号化されるべきデータが平文で扱われる可能性がある ・Tomcat クラスタ間通信などで機密データが漏えいする可能性がある ・機密性に高い影響が生じる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(SOCRadar) ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34486 ・https://tomcat.apache.org/security-11.html ・https://tomcat.apache.org/security-10.html ・https://tomcat.apache.org/security-9.html ・https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34486.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486 ・https://socradar.io/blog/snowlight-government-chinese-campaign/ ・https://jvndb.jvn.jp/ja/cwe/CWE-311.html ・https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has cataloged CVE‑2026‑9198, CVE‑2026‑18556, and CVE‑2026‑34486, providing detailed technical and patch information; active exploitation is confirmed for CVE‑2026‑18556.

    010935.3K
    45.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization CVE: CVE-2026-34486 PT ID: PT-2026-31712 Vendor: Apache Software Foundation Product: Apache Tomcat CVSS: n/a Credits: Bartlomiej Dmitruk, http://striga.ai Description: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34486 • https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly PoC/Exploit: https://github.com/striga-ai/CVE-2026-34486 #dbugs_vuln

    Post summary

    CVE-2026-34486 exposes unauthenticated RCE in Apache Tomcat through an EncryptInterceptor bypass; PoC and exploit code are available on GitHub, and users are advised to patch to the latest Tomcat releases.

    000311.2K
    2.6K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/08/04:Apache Tomcat の脆弱性 CVE-2026-34486 を登録 https://iototsecnews.jp/2026/08/04/cisa-warns-of-apache-tomcat-encryption-vulnerability-actively-exploited-in-attacks/ Apache Tomcat の深刻な脆弱性が、CISA KEV カタログに追加されました。Web アプリケーションの実行環境として広く用いられている Apache Tomcat において、通信の保護を妨害される深刻な不具合が確認されました。過去の修正漏れが原因で EncryptInterceptor が正常に機能せず、クラスタ環境内の暗号化メッセージを巧妙に偽装したデータが通過してしまいます。この問題により機密情報が流出し、第三者によるシステムへの侵入や悪意のあるプログラムの実行につながる危険性があります。脆弱性 CVE-2026-34486 (過去の CVE-2026-29146 に関連) への対応策として、修正プログラムが適用された最新版への速やかな更新が必要です。ご利用のチームは、ご注意ください。 #ApacheTomcat #CVE202634486 #CISA #KEV #Vulnerability #Exploit #OpenSource

    Post summary

    CISA advertises CVE-2026-34486 as actively exploited via Tomcat’s broken encryption interceptor, urging teams to update to the patched release.

    01000230
    507 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Apache Tomcat allowed bypass of EncryptInterceptor (CVE-2026-29146) https://www.systemtek.co.uk/2026/08/apache-tomcat-allowed-bypass-of-encryptinterceptor-cve-2026-29146/ via @SystemTek_UK

    Post summary

    The article announces CVE‑2026‑29146, noting that Apache Tomcat’s EncryptInterceptor can be bypassed, but offers no PoC, exploit code, or evidence of active exploitation.

    0001071
    1.8K followersView on X
  • GetAIGovernance@getaigovernance
    General

    Apache Tomcat CVE-2026-29146 Vulnerability Analysis-- @OligoSecurity https://getaigovernance.net/blog/apache-tomcat-cve-2026-29146-vulnerability-analysis

    Post summary

    The text indicates a blog analysis of Apache Tomcat CVE‑2026‑29146 but does not provide specific PoC, exploit, patch, or technical details.

    0001069
    1 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache Tomcat の脆弱性 CVE-2026-29146/34486/34500 が FIX:EncryptInterceptor バイパスの可能性 https://iototsecnews.jp/2026/04/13/apache-tomcat-flaws-enable-encryptinterceptor-bypass/ これらの Apache Tomcat の脆弱性は、暗号化の仕組みや修正時の不備が主な原因となっています。 CVE-2026-29146 では、暗号化モードの特性により外部から通信内容を推測される状態にありました。これを直そうとした際のコードの不備が CVE-2026-34486 という新たな問題を生み、セキュリティ機能自体が回避される結果を招いています。また CVE-2026-34500 では、証明書の失効を確認する際の処理が設定通りに動かず、本来拒否すべきアクセスを許可してしまう不備が発生しました。ご利用のチームは、ご注意ください。 #Apache #CVE202629146 #CVE202634486 #CVE202634500 #Tomcat #Vulnerability

    Post summary

    The article announces three new Apache Tomcat CVEs that allow bypassing encryption and certificate validation, detailing their technical causes and urging teams to be cautious.

    01000130
    486 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Apache ❗ CVE-2026-34486 ❗ CVE-2026-29146 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-apache-4/ https://t.co/qX4o1jGZll

    Post summary

    The tweet notes two new Apache CVEs but offers no specific technical, exploit, or mitigation details.

    00010120
    6.7K followersView on X
  • Gerald Beuchelt@beuchelt
    Active Exploitation

    Tomcat's own patch didn't close the hole. CVE-2026-34486 (CVSS 7.5) bypasses EncryptInterceptor because the fix for CVE-2026-29146 was incomplete. Real fix shipped in April. CISA's KEV Aug 4, FCEB deadline today. Two unrelated threat actors already exploited it. Verifying fixes, or just applying them? https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html

    Post summary

    CVE-2026-34486 in Tomcat was actively exploited by threat actors; the initial patch was incomplete, but a proper fix was released in April, and organizations are urged to apply the update before CISA's deadline.

    0000044
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29146 Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from… https://www.cve.org/CVERecord?id=CVE-2026-29146

    Post summary

    The post announces CVE-2026-29146, a Padding Oracle flaw in Apache Tomcat's EncryptInterceptor that impacts versions 11.0.0‑M1 to 11.0.18, but provides no evidence of exploitation or mitigation.

    00000121
    57.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34486 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affec… https://www.cve.org/CVERecord?id=CVE-2026-34486

    Post summary

    A brief disclosure of CVE‑2026‑34486, describing it as a missing encryption flaw in Apache Tomcat linked to a previous fix, without mention of exploits, active use, or remediation.

    00000550
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more