CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486 , to its Known Exploited Vulnerabilities catalog.
The agency said the vulnerability is being actively exploited and urged organizations to apply vendor mitigations before the August 7, 2026 deadline.
CVE-2026-34486 is a missing encryption of sensitive data vulnerability in Apache Tomcat. It is categorized under CWE-311, which covers failures to protect sensitive information with encryption.
The flaw allows attackers to bypass Tomcat’s EncryptInterceptor, a security component that encrypts communication in clustered Tomcat deployments.
An incomplete fix for the earlier CVE-2026-29146 vulnerability introduced the issue. Apache Tomcat’s EncryptInterceptor should prevent unencrypted or improperly encrypted cluster messages from reaching downstream components.
Apache Tomcat Encryption Vulnerability Exploited
However, the flawed implementation could allow specially crafted messages to bypass this protection, weakening confidentiality controls for cluster traffic.
The vulnerability affects Apache Tomcat 11.0.20, 10.1.53, and 9.0.116. Apache has released fixes in Tomcat 11.0.21, 10.1.54, and 9.0.117.
Organizations running the affected versions should upgrade immediately, especially where Tomcat clustering or Apache Tribes communication is enabled. Security researchers have linked CVE-2026-34486 to active exploitation attempts.
Unit 42 reported that a Chinese-speaking threat actor used the flaw during an AI-assisted attack campaign, with observed attempts to deploy Java deserialization-based reverse shells against vulnerable Apache Tomcat servers.
The activity shows how quickly attackers can incorporate newly disclosed enterprise software flaws into scanning and intrusion operations.
Although CISA has not confirmed that the Tomcat flaw has been used in ransomware campaigns, exploitation of internet-facing application servers can provide attackers with an initial foothold into corporate networks.
Once access is gained, threat actors may attempt credential theft, lateral movement, data theft, or malware deployment. The risk is higher for exposed Tomcat servers that use clustering features and accept traffic from untrusted networks.
Administrators should first identify all Tomcat deployments, including those hosted in cloud environments, container platforms, and internal application clusters.
Teams should confirm whether Apache Tribes clustering is enabled and determine whether vulnerable releases are in use. Applying the updated Tomcat versions is the primary remediation because it addresses the underlying EncryptInterceptor bypass.
Where an immediate update is not possible, defenders should limit access to Tomcat cluster communication ports so that only trusted cluster nodes can connect. Network segmentation, strict firewall rules , and private network paths can reduce exposure while patches are tested and deployed.
Organizations should also review Tomcat and network logs for unexpected cluster traffic, repeated encryption or decryption failures, and suspicious outbound connections.
CISA instructed federal civilian agencies to follow its Binding Operational Directive 26-04, which prioritizes remediation according to risk.
The agency also advised stakeholders to evaluate each asset’s internet exposure, follow its forensic triage requirements, and discontinue use of the product where effective mitigations are unavailable.
The short remediation window highlights the urgency of patch management for public-facing Java infrastructure. Security teams should treat CVE-2026-34486 as a priority, verify that encryption protections are working after the upgrade, and investigate any signs of unauthorized activity on exposed Apache Tomcat servers.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now .
The post CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News .
cybersecuritynews.com