Skip to content
Apache Tomcat Vulnerability CVE-2026-34486 Enables Remote Code Execution

Apache Tomcat Vulnerability CVE-2026-34486 Enables Remote Code Execution

First seen 7 Oct 2026, 15:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 17:29 UTC
  • •CVE-2026-34486 allows unauthenticated remote code execution in Apache Tomcat.
  • •The vulnerability was introduced by a single line change in a code refactor on March 13, 2026.
  • •CISA added the vulnerability to its KEV catalog on August 4, 2026, confirming active exploitation.

A vulnerability in Apache Tomcat, tracked as CVE-2026-34486, allows unauthenticated remote code execution due to a flaw in the EncryptInterceptor that bypasses encryption checks. This flaw was introduced by a code refactor on March 13, 2026, which moved a line of code, changing the encryption layer's behavior from fail-closed to fail-open. Attackers with network access to the Tribes receiver port (default TCP 4000) can exploit this vulnerability without needing credentials. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on August 4, 2026, indicating. The affected versions include Apache Tomcat 11.0.20, 10.1.53, and 9.0.116, which all shipped the flawed code. Patches were released in April 2026, but many systems remain. The vulnerability has been linked to a campaign deploying SNOWLIGHT malware using a deserialization chain.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-09
CVE-2026-29146 published
A padding oracle vulnerability in Apache Tomcat was disclosed, leading to a fix that introduced CVE-2026-34486.
Safe.Security
2026-04-15
First public PoC released
Proof-of-concept code demonstrating the exploit for CVE-2026-34486 was made publicly available.
Safe.Security
2026-08-04
CISA adds CVE-2026-34486 to KEV catalog
CISA confirmed active exploitation of the vulnerability in the wild, highlighting its severity.
Safe.Security
2026-10-07
Waratek and Striga report on vulnerability
Both companies published analyses detailing the vulnerability's introduction and its implications for security.
Waratek

More articles in this cluster (3)

Following this threat?

Track UNC5174, Snowlight and CVE-2026-29146 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Apache Tomcat are affected?
Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 are affected by CVE-2026-34486.
Is this vulnerability actively exploited?
Yes, CISA confirmed that CVE-2026-34486 is actively exploited in the wild.
What should organizations do to mitigate this risk?
Organizations should immediately apply the patches released for the affected versions to mitigate the risk.