Exploitation observed; activity peaked at 7 mentions and remains active
Immediate actions
Patch apache enterprise_linux systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github.
Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak.
https://github.com/striga-ai/CVE-2026-34486
https://github.com/striga-ai/CVE-2026-23918
Post summary
The post announces publicly available PoC exploits for Apache Tomcat and httpd RCE CVEs, asserting their reliability in lab settings.
The post outlines an attacker platform that discovers, enriches, and validates CVE exploits, listing multiple CVEs and affected systems but lacking specific exploit code, patch information, or evidence of real‑world exploitation.
Unauthenticated RCE in Apache Tomcat (CVE-2026-34486)
The EncryptInterceptor was supposed to protect cluster communication. A fix for a padding oracle vulnerability moved one line outside a try block, and the encryption layer silently started forwarding every failed decryption straight into unfiltered Java deserialization.
We found it with Striga, built the exploit, and reported it to The Apache Software Foundation.
https://www.striga.ai/research/tomcat-tribes-unauth-rce
Post summary
Researchers uncovered an unauthenticated RCE in Apache Tomcat caused by a misconfigured encryption interceptor, built a functional exploit, and published a PoC via their Striga research page.
The post announces that PoCs for two Apache vulnerabilities are publicly available on GitHub, outlines the technical nature of the flaws, and lists the affected and fixed versions, but makes no claim of current exploitation or false positives.
Fallo de seguridad en Apache Tomcat Tribes
La vulnerabilidad CVE-2026-34486 en Apache Tomcat Tribes surgió por un refactoring que cambió un diseño fail-closed a uno fail-open
https://blog.elhacker.net/2026/06/fallo-de-seguridad-en-apache-tomcat.html
Post summary
The post announces CVE‑2026‑34486 in Apache Tomcat Tribes, noting it was introduced by a refactoring error that switched from fail‑closed to fail‑open.
Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline.
The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes.
The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints.
The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized:
CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0
CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8
CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0
CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8
CVE-2026-25212 — Percona PMM RCE, CVSS 9.9
CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8
CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8
CVE-2026-42167 — ProFTPD
CVE-2026-6182 — SQL injection auth bypass
CVE-2025-24587, CVE-2025-4396
A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool.
The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray.
Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure.
One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations.
OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.
Post summary
The text details an ongoing, multi‑track attack operation actively weaponizing a list of high‑CVSS CVEs, employing custom scripts and exploitation tools.
Fun story:
#Apache patched a Tomcat padding oracle and shipped a worse bug doing it.
#CVE-2026-29146: EncryptInterceptor defaults to AES/CBC/PKCS5, a padding oracle.
No key needed, forge cluster messages on the Tribes receiver (TCP/4000, no peer auth) and you're a trusted node.
> The patch moved super.messageReceived() out of the try.
Then?
Decrypt fails, Tomcat deserializes your bytes anyway: badab00m!
That's CVE-2026-34486, pre-auth RCE!
Patch to be safe, pwn for the lulz 😎
> Fix: 9.0.117 / 10.1.54 / 11.0.21. Or GCM/NoPadding and keep 4000 off untrusted wires.
Whole story & details by @cyberkendra :
https://www.cyberkendra.com/2026/04/apache-tomcats-security-fix-opened-door.html
PoC from @striga_ai :
http://github.com/striga-ai/CVE-2026-34486
Post summary
The tweet announces two Apache Tomcat CVEs, provides technical details and a PoC link, and details patch versions and mitigations, indicating the availability of functional exploit code.
🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/mWcFU47aU3
Post summary
The tweet announces that three CVEs—CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486—have been added to the DHS KEV catalog, indicating they are currently exploited in the wild, and urges organizations to apply mitigations for protection.
⚠️⚠️ CVE-2026-34486 (CVSS 7.5): Striga detailed how a fail-open Tomcat Tribes regression may lead to unauthenticated RCE when clustering, EncryptInterceptor, and gadget classes are present.
Deep Dive: https://www.striga.ai/research/tomcat-tribes-unauth-rce
🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBUEFDSEUtVG9tY2F0Ig==
🎯4.7M+ Results are found on http://en.fofa.info in the past year.
FOFA Query: app="APACHE-Tomcat"
#OSINT#FOFA#CyberSecurity#Vulnerability
Post summary
Striga has disclosed a new Tomcat vulnerability (CVE‑2026‑34486) with an unauthenticated RCE scenario, offering a deep dive research link but no POC or patch information.
Not much on the menu today 😄
Found an exposed directory on 150.40.117[.]90:8000 with:
Tomcat Tribes / CVE-2026-34486 tooling
ActiveMQ CVE-2023-46604 exploit code
Docker API scripts targeting port 2375
JWT signature testing against tokens pulled from Elasticsearch
A few hardcoded targets and reverse-shell callbacks
The Tomcat payload simply runs id and writes the result into the webroot, while the ActiveMQ setup calls back to 150.40.117[.]90:8080.
Nothing too fancy today, just someone's exploit drawer left open 😅
If you've come across something interesting today, I'd like to see it too.
IOC: 150.40.117[.]90:8000
Post summary
The post reports finding an exposed directory containing exploitation code for Tomcat and ActiveMQ, along with Docker API scripts, but does not indicate active wild exploitation or mention patches.
🚨 CVE-2026-34486: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
EncryptInterceptor Bypass Enables Plaintext Credential Exfiltration
A regression introduced in the fix for CVE-2026-29146 inadvertently disabled proper enforcement of the EncryptInterceptor, allowing sensitive session data (e.g., authentication tokens, credentials) to be transmitted unencrypted over insecure channels despite configuration intent.
Full Vulnerability Details & Analysis at DarkEye:
🔗 https://darkeye.org/vuln/cve/CVE-2026-34486
🔍 Identify Targets via ZoomEye:
Filter: vul.cve="CVE-2026-34486"
Search Dork: app="Apache Tomcat"
Exposure: 562.9k+ instances identified globally.
ZoomEye Search Link:
👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJBcGFjaGUgVG9tY2F0Ig==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260414
#Tomcat#EncryptionBypass#CVE-2026-34486 #SessionSecurity#CryptoMisconfiguration#DarkEye
Post summary
Apache Tomcat’s CVE‑2026‑34486 vulnerability allows plaintext credential exfiltration due to a regression in a previous fix, exposing over 562,000 instances globally per ZoomEye, with technical details disclosed but no PoC, exploit, or patch referenced.
CVE-2026-34486: A one-line fix for a padding oracle in Apache Tomcat quietly disabled cluster encryption, enabling unauthenticated RCE.
16 years later, they've finally discovered our strategy @XorNinja 🤫
Post summary
The post highlights that a single‑line patch for a padding oracle in Apache Tomcat inadvertently disabled cluster encryption, which could enable unauthenticated remote code execution.
Daniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026
Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today.
1. CISA KEV / actively exploited (lead)
CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised.
CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today.
CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target.
CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today.
CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks.
2. Edge / network gear
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate.
Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched.
3. Microsoft / Windows / AD
Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap.
4. Web / cloud / DevOps
CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1.
CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep.
Watch / developing
Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks.
Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes.
Sources:
CISA — Adds Three KEVs (Aug 4)
CISA — Adds One KEV (Aug 3)
The Hacker News — CISA flags Langflow, Tomcat, N-central
Rapid7 — CVE-2026-18577 N-central exploited in the wild
N-able — N-central Security Update (Aug 2)
The Hacker News — Cisco FMC zero-day actively exploited
BleepingComputer — Rails Active Storage RCE (CVE-2026-66066)
BleepingComputer — WordPress wp2shell RCE public exploits
SecurityWeek — Fortinet/Ivanti critical patches
Senserva — CISA KEV additions this week
One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.
Post summary
The briefing details several CVEs that are actively exploited in the wild, provides PoC references, and specifies patches or mitigations, emphasizing immediate remediation.
🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik#GüvenlikBülteni
Merhaba #Brolyz
🎯 Zafiyet Bilgisi
Ürün: #Apache#Tomcat#Zafiyet: Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data)
CVE: CVE-2026-34486
Zafiyet Türü: Missing Encryption of Sensitive Data (CWE-311)
Fidye Yazılımı İlişkisi: Şu an için bilinmiyor.
📌 Zafiyet Özeti
Apache Tomcat üzerinde Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) zafiyeti tespit edilmiştir.
Bu güvenlik açığı, EncryptInterceptor bileşeninin atlatılmasına (bypass) olanak tanıyabilir. Ayrıca zafiyet, CVE-2025-24813 ile zincirleme (chained) olarak kullanıldığında daha kapsamlı saldırı senaryolarına zemin hazırlayabilir.
Başarılı bir istismarda saldırgan; hassas verileri riske atabilir, iletişim güvenliğini zayıflatabilir ve diğer zafiyetlerle sistemi ele geçirebilir.
🛡️ Önerilen Aksiyonlar
✅ Güvenlik Güncellemeleri
Apache tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın.
Apache Tomcat'i desteklenen en güncel sürüme yükseltin.
✅ Risk Yönetimi
Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin.
✅ Erişim Kontrolleri
İnternete açık Tomcat sunucularını öncelikli olarak değerlendirin.
Şifreleme yapılandırmalarını doğrulayın ve EncryptInterceptor kullanımını gözden geçirin.
Yönetim arayüzünü yalnızca güvenilir ağlardan erişilebilir hale getirin ve erişim kayıtlarını düzenli olarak izleyin.
✅ Geçici Koruma Önlemleri
Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, Tomcat sunucusunun internet erişimini sınırlandırın veya yalnızca VPN üzerinden erişilebilir hale getirin. Gerekirse etkilenen bileşenleri geçici olarak devre dışı bırakmayı değerlendirin.
📚 Referans: Apache Security Advisory & CISA
Post summary
A CVE-2026-34486 vulnerability in Apache Tomcat's EncryptInterceptor component is disclosed, with detailed impact analysis and recommended mitigation steps, including applying official security updates and upgrading to the latest supported version.
CISA added three CVEs to its known-exploited catalog; active exploitation is confirmed for CVE‑2026‑18556 and CVE‑2026‑34486, and vendor patches are available.
PoC for Apache Tomcat Unauth RCE (CVE-2026-34486) is now public.
Internet-facing Tomcat instances should be treated as high-priority patch targets immediately.
https://github.com/striga-ai/CVE-2026-34486
#CyberSecurity#Apache#Tomcat#RCE#CVE
Post summary
A proof of concept for CVE-2026-34486, an unauthenticated remote code execution vulnerability in Apache Tomcat, has been publicly released on GitHub; no active exploitation or patch information is mentioned.
CISAが既知の悪用された脆弱性3件をカタログに追加
CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4)
CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性
CVE-2026-18556 N-able N-central認証バイパス(代替パスまたはチャネルの使用)の脆弱性
CVE-2026-34486 Apache Tomcatにおける機密データの暗号化の欠落の脆弱性
https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
Post summary
CISA has added three CVEs with known exploitation to its catalog, highlighting the existence of real‑world attacks, but no PoC, exploit code, or patches are discussed.
The post provides a PoC link, functional exploit details, patch guidance, and technical vulnerability explanation, but does not mention active real-world exploitation.
Brilliant research! The fact that a padding oracle fix created an even worse deserialization pathway shows how interconnected these security layers are.
Apache Tomcat is everywhere in enterprise environments — this CVE-2026-34486 will be massive for patch teams: https://vulntracker.io
Post summary
The tweet notes that a padding oracle fix in Apache Tomcat has exposed a new deserialization vulnerability (CVE‑2026‑34486), likely to be a significant issue for patch teams, but offers no additional technical or exploit details.