CVE-2026-34486Disclosure(apache / enterprise_linux)

CRITICALCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch apache enterprise_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-311CWE-807

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_els
  • enterprise_linux_eus
  • enterprise_linux_tus

Threat summary

  • Active exploitation appears in 20 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 60 mentions across 31 observed days

What's happening

  • Active exploitation reported across 20 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 18 signals
  • Patch or workaround mentioned in 26 signals
  • Technical details provided in 49 signals
  • Disclosure: 18 classified signals
  • Peaked 12d ago at 7 mentions (2026-08-05); latest day: 1
  • 60 total mentions across 31 days

Affected systems

Products
enterprise_linuxenterprise_linux_elsenterprise_linux_eusenterprise_linux_tusenterprise_linux_update_services_for_sap_solutionsjboss_web_servertomcat

12 versions affected across 7 products

Deep dive

Activity timeline60 mentions / 31d
02457Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-13: 3Mentions · 2026-04-14: 6Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-04-29: 1Mentions · 2026-05-11: 4Mentions · 2026-05-12: 5Mentions · 2026-05-14: 1Mentions · 2026-05-28: 2Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-07-04: 1Mentions · 2026-07-17: 1Mentions · 2026-08-04: 2Mentions · 2026-08-05: 7Mentions · 2026-08-06: 4Mentions · 2026-08-07: 3Mentions · 2026-08-08: 2Mentions · 2026-08-09: 1Mentions · 2026-08-10: 2Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Mentions · 2026-08-20: 1Mentions · 2026-08-30: 1Mentions · 2026-09-03: 1Mentions · 2026-09-12: 1Mentions · 2026-09-19: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-11: 4PoC Mentioned / Linked · 2026-05-12: 4PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-28: 1PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-07-04: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-08: 1PoC Mentioned / Linked · 2026-08-20: 1Exploit Tool / Code · 2026-04-13: 1Exploit Tool / Code · 2026-04-29: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-05-12: 2Exploit Tool / Code · 2026-05-14: 1Exploit Tool / Code · 2026-07-04: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-08-08: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-08-04: 2Active Exploitation · 2026-08-05: 5Active Exploitation · 2026-08-06: 2Active Exploitation · 2026-08-07: 2Active Exploitation · 2026-08-08: 2Active Exploitation · 2026-08-09: 1Active Exploitation · 2026-08-10: 2Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-08-30: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-04-13: 2Patch / Workaround · 2026-04-14: 3Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-08-05: 4Patch / Workaround · 2026-08-06: 3Patch / Workaround · 2026-08-07: 2Patch / Workaround · 2026-08-08: 2Patch / Workaround · 2026-08-10: 2Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-14: 5Technical Details · 2026-04-16: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-11: 4Technical Details · 2026-05-12: 4Technical Details · 2026-05-14: 1Technical Details · 2026-05-28: 2Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-05: 6Technical Details · 2026-08-06: 4Technical Details · 2026-08-07: 1Technical Details · 2026-08-08: 2Technical Details · 2026-08-10: 2Technical Details · 2026-08-12: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-19: 104-0904-1404-2005-1105-2807-0408-0508-0808-1108-3009-19
Signal classification6 categories
Disclosure
1830.0%
Active Exploitation
1728.3%
Patch
711.7%
PoC
711.7%
General
610.0%
Exploit
58.3%
Referenced assets65 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-04-101
Disclosure1
2026-04-133
Disclosure2Exploit1
2026-04-146
Disclosure4General1Patch1
2026-04-151
Disclosure1
2026-04-161
Disclosure1
2026-04-201
Disclosure1
2026-04-211
Patch1
2026-04-291
Exploit1
2026-05-114
Exploit1General1PoC2
2026-05-125
General1PoC4
2026-05-141
PoC1
2026-05-282
Disclosure2
2026-06-251
Disclosure1
2026-06-261
Disclosure1
2026-07-041
Exploit1
2026-07-171
Active Exploitation1
2026-08-042
Active Exploitation2
2026-08-057
Active Exploitation4Disclosure2Patch1
2026-08-064
Active Exploitation2Patch2
2026-08-073
Active Exploitation2General1
2026-08-082
Active Exploitation2
2026-08-091
Active Exploitation1
2026-08-102
Active Exploitation1Patch1
2026-08-111
General1
2026-08-121
Active Exploitation1
2026-08-201
Exploit1
2026-08-301
Patch1
2026-09-031
General1
2026-09-121
Active Exploitation1
2026-09-191
Disclosure1
Full discourse20 posts
  • striga@striga_ai
    Exploit

    PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak. https://github.com/striga-ai/CVE-2026-34486 https://github.com/striga-ai/CVE-2026-23918

    Post summary

    The post announces publicly available PoC exploits for Apache Tomcat and httpd RCE CVEs, asserting their reliability in lab settings.

    4180673351795.3K
    536 followersView on X
  • Densel@luckyhacker43
    Disclosure

    Unauthenticated RCE in Apache Tomcat (CVE-2026-34486) 🤯🔥 🔗 https://www.striga.ai/research/tomcat-tribes-unauth-rce 🔗 Join team today 👉https://t.me/luckyhacker43 https://t.co/5R0YJ4BBUQ

    Post summary

    A new unauthenticated RCE vulnerability in Apache Tomcat (CVE-2026-34486) has been disclosed, with a research link provided for details.

    492043829839.0K
    3.6K followersView on X
  • Sans Limite@SansLimit3
    General

    Exposed attacker infrastructure combining #Hermes Agent, #CyberStrikeAI, #SliverC2, and multiple LLMs used for automated CVE targeting, exploit validation, Telegram-based orchestration, and post-exploitation validation workflows. Opendir: 142.171.160[.]137:8888 VULN-MONITOR: 142.171.149[.169:8001 - Real-time 1day/0day RCE tracking across 18 sources🤔 CyberStrikeAI Server: 100.81.245[.29:8080 Chain: FOFA/Shodan recon → AI-assisted target filtering → CVE/PoC enrichment → custom scanner & exploit generation → exploit validation → WebSocket/shell access → post-exploitation environment validation → Telegram-pushed operations. Targeted CVEs: CVE-2026-0300 (Palo Alto PAN-OS) CVE-2024-21762 (FortiOS/FortiProxy SSL-VPN) CVE-2026-33017 (Langflow) CVE-2026-21858 (n8n) CVE-2026-3055 (Citrix ADC/NetScaler) CVE-2026-34486 (Apache Tomcat) CVE-2026-25253 (OpenClaw/Moltbot/Clawdbot) @malwrhunterteam @500mk500 @1ZRR4H @MichalKoczwara

    Post summary

    The post outlines an attacker platform that discovers, enriches, and validates CVE exploits, listing multiple CVEs and affected systems but lacking specific exploit code, patch information, or evidence of real‑world exploitation.

    837223619525.2K
    634 followersView on X
  • striga@striga_ai
    Exploit

    Unauthenticated RCE in Apache Tomcat (CVE-2026-34486) The EncryptInterceptor was supposed to protect cluster communication. A fix for a padding oracle vulnerability moved one line outside a try block, and the encryption layer silently started forwarding every failed decryption straight into unfiltered Java deserialization. We found it with Striga, built the exploit, and reported it to The Apache Software Foundation. https://www.striga.ai/research/tomcat-tribes-unauth-rce

    Post summary

    Researchers uncovered an unauthenticated RCE in Apache Tomcat caused by a misconfigured encryption interceptor, built a functional exploit, and published a PoC via their Striga research page.

    465423513929.9K
    537 followersView on X
  • yousukezan@yousukezan
    PoC

    Apache Tomcat の認証なし RCE (CVE-2026-34486) および Apache httpd の認証前 RCE (CVE-2026-23918) の PoC が、GitHub で公開されている。 CVE-2026-34486は、クラスタリング機能であるTribesのEncryptInterceptorにおいて、暗号化処理の失敗時に通信を許可してしまう「fail-open」動作が原因である。本来は暗号化されるべき通信が未検証のまま受け入れられ、Javaのデシリアライズ処理と組み合わさることで、認証なしでリモートコード実行(RCE)が可能となる重大な問題となっている。 影響を受けるのはTomcat 9.0.116以降、10.1.53以降、11.0.19以降で、修正版はそれぞれ9.0.117、10.1.54、11.0.21で提供されている。 CVE-2026-23918は、HTTP/2機能を提供するmod_http2モジュールにおけるダブルフリー(double-free)バグで、ストリーム終了処理中のメモリ管理不備が原因となっている。これにより、認証前の段階でリモートコード実行(RCE)が可能になる重大な問題である。影響を受けるのは、マルチスレッド型MPM(event/worker)を使用したhttpd 2.4.66であり、バージョン2.4.67で修正されている。 https://github.com/striga-ai/CVE-2026-34486 https://github.com/striga-ai/CVE-2026-23918

    Post summary

    The post announces that PoCs for two Apache vulnerabilities are publicly available on GitHub, outlines the technical nature of the flaws, and lists the affected and fixed versions, but makes no claim of current exploitation or false positives.

    164322813119.8K
    14.5K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Fallo de seguridad en Apache Tomcat Tribes La vulnerabilidad CVE-2026-34486 en Apache Tomcat Tribes surgió por un refactoring que cambió un diseño fail-closed a uno fail-open https://blog.elhacker.net/2026/06/fallo-de-seguridad-en-apache-tomcat.html

    Post summary

    The post announces CVE‑2026‑34486 in Apache Tomcat Tribes, noting it was introduced by a refactoring error that switched from fail‑closed to fail‑open.

    1280104279.5K
    141.3K followersView on X
  • Yusuf Can Çakır@Yusufcancakiir
    Active Exploitation

    Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline. The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes. The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints. The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized: CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0 CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8 CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0 CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8 CVE-2026-25212 — Percona PMM RCE, CVSS 9.9 CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8 CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8 CVE-2026-42167 — ProFTPD CVE-2026-6182 — SQL injection auth bypass CVE-2025-24587, CVE-2025-4396 A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool. The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray. Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure. One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations. OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.

    Post summary

    The text details an ongoing, multi‑track attack operation actively weaponizing a list of high‑CVSS CVEs, employing custom scripts and exploitation tools.

    215054404.8K
    1.6K followersView on X
  • kmkz@kmkz_security
    Exploit

    Fun story: #Apache patched a Tomcat padding oracle and shipped a worse bug doing it. #CVE-2026-29146: EncryptInterceptor defaults to AES/CBC/PKCS5, a padding oracle. No key needed, forge cluster messages on the Tribes receiver (TCP/4000, no peer auth) and you're a trusted node. > The patch moved super.messageReceived() out of the try. Then? Decrypt fails, Tomcat deserializes your bytes anyway: badab00m! That's CVE-2026-34486, pre-auth RCE! Patch to be safe, pwn for the lulz 😎 > Fix: 9.0.117 / 10.1.54 / 11.0.21. Or GCM/NoPadding and keep 4000 off untrusted wires. Whole story & details by @cyberkendra : https://www.cyberkendra.com/2026/04/apache-tomcats-security-fix-opened-door.html PoC from @striga_ai : http://github.com/striga-ai/CVE-2026-34486

    Post summary

    The tweet announces two Apache Tomcat CVEs, provides technical details and a PoC link, and details patch versions and mitigations, indicating the availability of functional exploit code.

    013067305.4K
    19.8K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/mWcFU47aU3

    Post summary

    The tweet announces that three CVEs—CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486—have been added to the DHS KEV catalog, indicating they are currently exploited in the wild, and urges organizations to apply mitigations for protection.

    719143711.1K
    303.2K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-34486 (CVSS 7.5): Striga detailed how a fail-open Tomcat Tribes regression may lead to unauthenticated RCE when clustering, EncryptInterceptor, and gadget classes are present. Deep Dive: https://www.striga.ai/research/tomcat-tribes-unauth-rce 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBUEFDSEUtVG9tY2F0Ig== 🎯4.7M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="APACHE-Tomcat" #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    Striga has disclosed a new Tomcat vulnerability (CVE‑2026‑34486) with an unauthenticated RCE scenario, offering a deep dive research link but no POC or patch information.

    011037182.8K
    14.3K followersView on X
  • Yusuf Can Çakır@Yusufcancakiir
    Exploit

    Not much on the menu today 😄 Found an exposed directory on 150.40.117[.]90:8000 with: Tomcat Tribes / CVE-2026-34486 tooling ActiveMQ CVE-2023-46604 exploit code Docker API scripts targeting port 2375 JWT signature testing against tokens pulled from Elasticsearch A few hardcoded targets and reverse-shell callbacks The Tomcat payload simply runs id and writes the result into the webroot, while the ActiveMQ setup calls back to 150.40.117[.]90:8080. Nothing too fancy today, just someone's exploit drawer left open 😅 If you've come across something interesting today, I'd like to see it too. IOC: 150.40.117[.]90:8000

    Post summary

    The post reports finding an exposed directory containing exploitation code for Tomcat and ActiveMQ, along with Docker API scripts, but does not indicate active wild exploitation or mention patches.

    25025121.7K
    1.7K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-34486: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor EncryptInterceptor Bypass Enables Plaintext Credential Exfiltration A regression introduced in the fix for CVE-2026-29146 inadvertently disabled proper enforcement of the EncryptInterceptor, allowing sensitive session data (e.g., authentication tokens, credentials) to be transmitted unencrypted over insecure channels despite configuration intent. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-34486 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-34486" Search Dork: app="Apache Tomcat" Exposure: 562.9k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgVG9tY2F0Ig==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260414 #Tomcat #EncryptionBypass #CVE-2026-34486 #SessionSecurity #CryptoMisconfiguration #DarkEye

    Post summary

    Apache Tomcat’s CVE‑2026‑34486 vulnerability allows plaintext credential exfiltration due to a regression in a previous fix, exposing over 562,000 instances globally per ZoomEye, with technical details disclosed but no PoC, exploit, or patch referenced.

    0602396.9K
    12.2K followersView on X
  • Juliano Rizzo@julianor
    Patch

    CVE-2026-34486: A one-line fix for a padding oracle in Apache Tomcat quietly disabled cluster encryption, enabling unauthenticated RCE. 16 years later, they've finally discovered our strategy @XorNinja 🤫

    Post summary

    The post highlights that a single‑line patch for a padding oracle in Apache Tomcat inadvertently disabled cluster encryption, which could enable unauthenticated remote code execution.

    2202373.0K
    9.5K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026 Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today. 1. CISA KEV / actively exploited (lead) CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised. CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today. CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target. CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today. CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks. 2. Edge / network gear CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate. Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched. 3. Microsoft / Windows / AD Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap. 4. Web / cloud / DevOps CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1. CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep. Watch / developing Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks. Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes. Sources: CISA — Adds Three KEVs (Aug 4) CISA — Adds One KEV (Aug 3) The Hacker News — CISA flags Langflow, Tomcat, N-central Rapid7 — CVE-2026-18577 N-central exploited in the wild N-able — N-central Security Update (Aug 2) The Hacker News — Cisco FMC zero-day actively exploited BleepingComputer — Rails Active Storage RCE (CVE-2026-66066) BleepingComputer — WordPress wp2shell RCE public exploits SecurityWeek — Fortinet/Ivanti critical patches Senserva — CISA KEV additions this week One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.

    Post summary

    The briefing details several CVEs that are actively exploited in the wild, provides PoC references, and specifies patches or mitigations, emphasizing immediate remediation.

    22015612.7K
    126.0K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: #Apache #Tomcat #Zafiyet: Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) CVE: CVE-2026-34486 Zafiyet Türü: Missing Encryption of Sensitive Data (CWE-311) Fidye Yazılımı İlişkisi: Şu an için bilinmiyor. 📌 Zafiyet Özeti Apache Tomcat üzerinde Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) zafiyeti tespit edilmiştir. Bu güvenlik açığı, EncryptInterceptor bileşeninin atlatılmasına (bypass) olanak tanıyabilir. Ayrıca zafiyet, CVE-2025-24813 ile zincirleme (chained) olarak kullanıldığında daha kapsamlı saldırı senaryolarına zemin hazırlayabilir. Başarılı bir istismarda saldırgan; hassas verileri riske atabilir, iletişim güvenliğini zayıflatabilir ve diğer zafiyetlerle sistemi ele geçirebilir. 🛡️ Önerilen Aksiyonlar ✅ Güvenlik Güncellemeleri Apache tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın. Apache Tomcat'i desteklenen en güncel sürüme yükseltin. ✅ Risk Yönetimi Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin. ✅ Erişim Kontrolleri İnternete açık Tomcat sunucularını öncelikli olarak değerlendirin. Şifreleme yapılandırmalarını doğrulayın ve EncryptInterceptor kullanımını gözden geçirin. Yönetim arayüzünü yalnızca güvenilir ağlardan erişilebilir hale getirin ve erişim kayıtlarını düzenli olarak izleyin. ✅ Geçici Koruma Önlemleri Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, Tomcat sunucusunun internet erişimini sınırlandırın veya yalnızca VPN üzerinden erişilebilir hale getirin. Gerekirse etkilenen bileşenleri geçici olarak devre dışı bırakmayı değerlendirin. 📚 Referans: Apache Security Advisory & CISA

    Post summary

    A CVE-2026-34486 vulnerability in Apache Tomcat's EncryptInterceptor component is disclosed, with detailed impact analysis and recommended mitigation steps, including applying official security updates and upgrading to the latest supported version.

    030110107
    521 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/04追加) #vulnerability 🛡CVE-2026-9198 IBM Langflow Code Injection Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / IBM Corporation (CNA) ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H IBM Langflow OSS 1.0.0 から 1.10.0 に存在するコードインジェクションの脆弱性です。 未認証の攻撃者が /api/v1/auto_login で SUPERUSER トークンを取得し、/api/v1/validate/code で任意コードを実行することで、既定構成の Langflow 環境でリモートコード実行に至る可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・IBM Langflow OSS 1.0.0 から 1.10.0 を使用している ・/api/v1/auto_login がネットワーク経由で到達可能である ・/api/v1/validate/code がネットワーク経由で到達可能である ・既定構成で auto-login 機能が有効である ・Langflow OSS 1.10.1 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者に SUPERUSER トークンを取得される可能性がある ・Langflow のコード検証機能を悪用される可能性がある ・対象ホスト上で任意の Python コードを実行される可能性がある ・APIキー、環境変数、外部連携先の認証情報を窃取される可能性がある ・Langflow 環境を起点に追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-9198 ・https://www.ibm.com/support/pages/node/7278927 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9198.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198 ・https://jvndb.jvn.jp/ja/cwe/CWE-94.html 🛡CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / N-able (CNA) ・種別:代替パスまたはチャネルを使用した認証回避 (CWE-288) ・CVSS:CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N N-able N-central に存在する、代替パスまたはチャネルを使用した認証回避の脆弱性です。 N-central 2026.1 までのバージョンが影響を受け、認証バイパスにつながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・N-able N-central 2026.1 以前を使用している ・攻撃者が N-central サーバーへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・N-central 2026.3.1.7 以降へ更新されていない ・関連する修正済みホットフィックスが適用されていない ✅悪用時影響 ・認証をバイパスされる可能性がある ・N-central サーバーへの管理アクセス取得につながる可能性がある ・管理対象エンドポイントへ到達される可能性がある ・Take Control 機能などを悪用される可能性がある ・Cloudflare Tunnel などを用いた永続化に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(N-able) ・概要:N-able は、2026年7月31日に Adlumin MDR が顧客環境で不審な活動を検知し、N-central サーバーのゼロデイ悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-18556 ・https://www.n-able.com/blog/n-central-security-update-august-4-2026 ・https://uptime.n-able.com/ ・https://github.com/cisagov/vulnrichment/blob/develop/2026/18xxx/CVE-2026-18556.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556 ・https://jvndb.jvn.jp/ja/cwe/CWE-288.html 🛡CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / CISA-ADP ・種別:重要なデータの暗号化の欠如 (CWE-311) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Apache Tomcat の EncryptInterceptor に存在する、重要なデータの暗号化の欠如に関する脆弱性です。 CVE-2026-29146 の修正に起因して EncryptInterceptor のバイパスが可能となり、機密データが暗号化されない可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:部分的 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・Apache Tomcat 11.0.20、10.1.53、または 9.0.116 を使用している ・Tomcat クラスタリング等で EncryptInterceptor を使用している ・攻撃者が EncryptInterceptor により保護される通信経路へ影響を及ぼせる ・Apache Tomcat 11.0.21、10.1.54、または 9.0.117 以降へ更新されていない ・CVE-2026-29146 の修正を含む影響バージョンを利用している ✅悪用時影響 ・EncryptInterceptor による暗号化をバイパスされる可能性がある ・本来暗号化されるべきデータが平文で扱われる可能性がある ・Tomcat クラスタ間通信などで機密データが漏えいする可能性がある ・機密性に高い影響が生じる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(SOCRadar) ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34486 ・https://tomcat.apache.org/security-11.html ・https://tomcat.apache.org/security-10.html ・https://tomcat.apache.org/security-9.html ・https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34486.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486 ・https://socradar.io/blog/snowlight-government-chinese-campaign/ ・https://jvndb.jvn.jp/ja/cwe/CWE-311.html ・https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added three CVEs to its known-exploited catalog; active exploitation is confirmed for CVE‑2026‑18556 and CVE‑2026‑34486, and vendor patches are available.

    010935.3K
    45.6K followersView on X
  • DarkRelay Security Labs@darkrelaylabs
    PoC

    PoC for Apache Tomcat Unauth RCE (CVE-2026-34486) is now public. Internet-facing Tomcat instances should be treated as high-priority patch targets immediately. https://github.com/striga-ai/CVE-2026-34486 #CyberSecurity #Apache #Tomcat #RCE #CVE

    Post summary

    A proof of concept for CVE-2026-34486, an unauthenticated remote code execution vulnerability in Apache Tomcat, has been publicly released on GitHub; no active exploitation or patch information is mentioned.

    00062325
    145 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4) CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性 CVE-2026-18556 N-able N-central認証バイパス(代替パスまたはチャネルの使用)の脆弱性 CVE-2026-34486 Apache Tomcatにおける機密データの暗号化の欠落の脆弱性 https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added three CVEs with known exploitation to its catalog, highlighting the existence of real‑world attacks, but no PoC, exploit code, or patches are discussed.

    01023317
    5.0K followersView on X
  • Y11@seclink
    Exploit

    CVE-2026-34486:Apache Tomcat 远程代码执行漏洞 (RCE) https://github.com/punitdarji/tomcat-cve-2026-34486 注意: POC 仅用于授权安全研究,严禁用于非法攻击。 实际生产环境若未启用 Tribes 集群或 EncryptInterceptor,则不受影响。 修复方式:立即升级 到修复版本,或移除EncryptInterceptor 配置(若不需要集群加密)。 漏洞原理:Fail-Open 逻辑错误 漏洞点位于 EncryptInterceptor.messageReceived() 方法。 修复前(安全):解密逻辑在 try 块内,若解密失败(抛出异常),消息处理流程中断。 修复后(漏洞):核心处理逻辑 super.messageReceived(msg) 被错误地移到了 try-catch 块之外。 攻击链条: 发送载荷:攻击者向集群端口发送未经加密的恶意 Java 序列化对象(如 ysoserial 生成的 Payload)。 解密失败:EncryptInterceptor 尝试解密,由于数据未加密会触发异常。 继续传递:由于逻辑错误,程序忽略异常,并将原始的恶意字节流继续传递给后续拦截器。 触发 RCE:数据最终进入 ObjectInputStream.readObject() 进行反序列化,若 Classpath 中存在可用 Gadget(如 CommonsCollections),即可实现远程代码执行。 4. 复现与验证 (POC) 已有公开 POC 证明该漏洞高度可利用。 核心逻辑:构造 Tribes 协议帧 -> 封装序列化 Payload -> 发送至目标 4000 端口。 隐蔽性:攻击发生时,Tomcat 日志仅记录解密异常,不会抛出明显的全堆栈反序列化报错。 5. 修复建议 立即升级:更新至官方最新安全版本。 临时规避:若无法立即升级,建议在防火墙层面关闭 4000 端口的外部访问,或暂时移除 EncryptInterceptor 配置。 深度防御:在 JVM 启动参数中配置反序列化过滤器(ObjectInputFilter),限制可实例化的类。

    Post summary

    The post provides a PoC link, functional exploit details, patch guidance, and technical vulnerability explanation, but does not mention active real-world exploitation.

    11022629
    29.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    Brilliant research! The fact that a padding oracle fix created an even worse deserialization pathway shows how interconnected these security layers are. Apache Tomcat is everywhere in enterprise environments — this CVE-2026-34486 will be massive for patch teams: https://vulntracker.io

    Post summary

    The tweet notes that a padding oracle fix in Apache Tomcat has exposed a new deserialization vulnerability (CVE‑2026‑34486), likely to be a significant issue for patch teams, but offers no additional technical or exploit details.

    00033383
    672 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat10.1.53--
Appapachetomcat11.0.20--
Appapachetomcat9.0.116--
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_els7.0--
OSredhatenterprise_linux_eus10.0--
OSredhatenterprise_linux_tus8.8--
OSredhatenterprise_linux_update_services_for_sap_solutions8.8--
OSredhatenterprise_linux_update_services_for_sap_solutions9.2--
OSredhatenterprise_linux_update_services_for_sap_solutions9.4--
OSredhatenterprise_linux_update_services_for_sap_solutions9.6--
Appredhatjboss_web_server7.0.0--

Explore more