---
schema: 1
kind: vulnerability
title: "CVE-2026-34486 — Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting it"
headline: "Tomcat clustering flaw KEV-listed in August — SNOWLIGHT operators were exploiting it in April"
summary: >
  CISA added CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on 2026-08-04. The Tomcat
  security team's own description is narrow: an error in the fix for CVE-2026-29146 allowed the
  EncryptInterceptor to be bypassed, and only the three releases that carried that broken fix — 9.0.116,
  10.1.53 and 11.0.20 — are affected. What the KEV listing does not convey is the timing: SOCRadar's
  analysis of an exposed adversary staging server records the flaw being exploited against Taiwanese
  targets in late April 2026, weeks after the 9 April disclosure, as a Java deserialization path
  delivering the SNOWLIGHT loader. The exploitation is more than three months old; the catalog entry is new.
discovered_at: "2026-08-05T04:12:23Z"
event_date: "2026-08-04"
run_id: 2026-08-05T0412Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, actively-exploited, cisa-kev, patch-available, nation-state]
regions: [global, europe, apac]
sectors: [public-sector, finance, healthcare, telco]
entities: [malware:snowlight, actor:unc5174, actor:unc6586]
techniques: [T1190, T1210]
affected_products: ["Apache Tomcat"]
cves:
  - id: CVE-2026-34486
    cvss: "7.5"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Apache Tomcat 9.0.116, 10.1.53 and 11.0.20 only — the three releases that shipped the defective fix for CVE-2026-29146. Exploitable where clustering is enabled with EncryptInterceptor configured and the Tribes receiver is network-reachable."
    fixed: "9.0.117, 10.1.54 and 11.0.21 — released 2026-04-04, made public 2026-04-09."
sources:
  - url: "https://tomcat.apache.org/security-11.html"
    publisher: "Apache Software Foundation (Tomcat security team)"
    date: "2026-04-09"
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog"
    publisher: "CISA"
    date: "2026-08-04"
    role: corroborating
  - url: "https://socradar.io/blog/snowlight-government-chinese-campaign/"
    publisher: "SOCRadar"
    date: "2026-07-31"
    role: corroborating
closed_sources: []
evidence:
  - quote: "An error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed."
    publisher: "Apache Software Foundation (Tomcat security team)"
  - quote: "Apache Tomcat Missing Encryption of Sensitive Data Vulnerability"
    publisher: "CISA"
  - quote: "CVE-2026-34486 (Java deserialization, CommonsCollections6 gadget) – Taiwan-focused, delivers SNOWLIGHT"
    publisher: "SOCRadar"
verification: multi-source
sourcing_note: "Apache is the primary for the defect and the affected releases; the entry's earlier draft carried the adjacent CVE-2026-34487 version ranges and has been corrected to the three releases Apache and the CVE record actually name. The CVSS 7.5 is carried by neither cited source: Apache's CNA container rates the flaw only textually as 'important', and the numeric score with its confidentiality-only vector (C:H/I:N/A:N) comes from the CISA-ADP and Red Hat enrichment containers on the CVE record. That vector understates what SOCRadar reports observing — live command execution — which is why this entry types it as remote code execution on SOCRadar's evidence rather than on the score. The deserialization mechanism and the exploitation attribution come from SOCRadar, not from Apache or CISA."
confidence: high
update_of: null
references:
  - 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 1
watchlist_hit: false
actions:
  - "Upgrade Tomcat 9.0.116, 10.1.53 or 11.0.20 to 9.0.117, 10.1.54 or 11.0.21 — and because exploitation predates the KEV listing by more than three months, treat any clustered instance that ran one of those three releases with a reachable Tribes receiver as a compromise-assessment target rather than a patching task."
  - "Firewall the Tribes receiver port to the declared cluster members only; a non-member speaking Tribes has no legitimate reason to exist, and this removes the precondition independently of the upgrade."
migrated_from: null
---

CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog on 2026-08-04, listing it as an Apache Tomcat missing-encryption-of-sensitive-data vulnerability ([CISA, 2026-08-04](https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog)). The defect is a regression in a security fix: the Tomcat security team records that an error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed ([Apache Software Foundation, 2026-04-09](https://tomcat.apache.org/security-11.html)). That is the whole of the vendor's description, and it carries an important consequence for scoping — only the three releases that shipped the defective fix are affected: 9.0.116, 10.1.53 and 11.0.20. An estate on an older release never received the broken fix and is not exposed to this flaw. The corrected builds are 9.0.117, 10.1.54 and 11.0.21, released 2026-04-04 and public from 2026-04-09.

**The exploitation is not new, and that is the finding.** SOCRadar's analysis of an exposed adversary staging server places this CVE in an active China-nexus campaign months before the catalog entry, recording it as a Java deserialization path using a CommonsCollections6 gadget, Taiwan-focused, delivering the SNOWLIGHT loader ([SOCRadar, 2026-07-31](https://socradar.io/blog/snowlight-government-chinese-campaign/)). SOCRadar's own timeline puts that exploitation in late April 2026 — within weeks of the 9 April public disclosure — and its per-CVE table records confirmed live command execution against targets. SOCRadar attributes the SNOWLIGHT family, tracked by Google's threat-intelligence group, to China-nexus access brokers UNC5174 and UNC6586, and describes a campaign whose targeting centres on government infrastructure.

So the honest reading of the KEV addition is not "attackers have started". It is that a defender relying on the catalog as their exploitation signal was, for this flaw, more than three months behind an actor already using it against government targets. That is worth internalising beyond this CVE: KEV records exploitation the catalog has confirmed, not exploitation that exists, and a KEV-driven patch queue inherits that lag.

Note also the scoring tension. Apache's own CNA entry rates the flaw only as 'important' in words; the numeric 7.5 and its confidentiality-only vector come from the CISA and Red Hat enrichment containers on the CVE record, and CISA's alert title frames the flaw as missing encryption of sensitive data — both consistent with "the encrypted cluster channel stopped being encrypted". SOCRadar reports command execution. A team triaging on the CVSS vector alone would have ranked this well below its demonstrated impact.

**The exposure profile is narrow, and inverted from the usual instinct.** Three conditions must hold: clustering enabled, EncryptInterceptor configured, and the Tribes receiver reachable. The middle one is the uncomfortable part — the exposed population is the operators who turned encryption on for session replication rather than leaving the channel in the clear.

Detection concepts, telemetry class first. Network-flow and firewall telemetry is the cleanest surface, because Tribes membership is normally a fixed, small mesh of known peers: a session to the configured receiver port from any source outside the declared membership has no legitimate explanation. On the host, process-creation telemetry with parent lineage showing a Tomcat or Catalina JVM spawning a shell or a command interpreter is the deserialization payoff, and SOCRadar's recorded operator behaviour — command-execution oracles such as `id` and `whoami` run per host — is what the reconnaissance stage looks like. In application logs, an EncryptInterceptor decryption-failure entry followed by successful message processing rather than a discard is the mechanism itself firing.

**Triage:** a decryption-failure log line alone is not the signal — clock skew, a rolling upgrade with mismatched keys, or a misconfigured new node all produce them, and in those cases the message is dropped and the peer is a known member. The discriminators are whether processing continued after the failure, and whether the source address belongs to the declared membership list.

**Defender takeaway:** patch the three affected releases, firewall the receiver to declared members, and — because exploitation predates the catalog listing by more than three months — treat a clustered instance that ran 9.0.116, 10.1.53 or 11.0.20 with a reachable receiver as needing a look for execution artefacts rather than just an upgrade. Asset teams should note the exposure is not limited to deliberately installed Tomcat: it ships embedded inside a long tail of appliances and commercial products, and an embedded clustered runtime is as reachable as a standalone one.
