VYPR
kevPublished Aug 9, 2026· 1 source

CISA Adds Apache Tomcat Encryption Flaw to KEV, Exploited by AI-Assisted Attackers

CISA has added CVE-2026-34486, a critical Apache Tomcat encryption bypass vulnerability, to its Known Exploited Vulnerabilities catalog, with threat actors reportedly using AI to aid exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-34486, a significant vulnerability affecting Apache Tomcat, to its Known Exploited Vulnerabilities (KEV) catalog. This directive mandates that federal agencies patch or remediate the flaw by August 7, 2026, highlighting its severity and active exploitation.

The vulnerability, identified as a missing-encryption flaw within Tomcat's EncryptInterceptor, stems from an incomplete patch for a previous issue, CVE-2026-29146. It allows attackers to bypass encryption protections on clustered Tomcat traffic, specifically impacting communication facilitated by Apache Tribes. Affected versions include Tomcat 11.0.20, 10.1.53, and 9.0.116.

Adding a concerning layer to this exploitation, Unit 42 researchers observed a Chinese-speaking threat actor leveraging this vulnerability in an AI-assisted campaign. This campaign reportedly deployed Java deserialization-based reverse shells, indicating a growing trend of threat actors integrating artificial intelligence into their attack methodologies to enhance efficiency and stealth.

Apache has responded by releasing updated versions of Tomcat: 11.0.21, 10.1.54, and 9.0.117, which address the vulnerability. For organizations unable to apply these patches immediately, CISA recommends implementing network-level mitigations. These include restricting access to cluster communication ports and diligently monitoring for any signs of encryption failures or unusual outbound network traffic that could indicate compromise.

This advisory also touches upon other critical security issues, including an 18-year-old Linux kernel flaw (CVE-2026-64564) that enables local privilege escalation to root, even within containerized environments. Patches for this long-standing vulnerability are available for affected stable kernels. Additionally, the roundup mentions critical bugs affecting N-able N-Central, Veeam ONE, Jenkins, and Cisco IOS XE, alongside a wave of AI-security incidents impacting platforms like Claude and code editors such as Cursor and VS Code.

The inclusion of CVE-2026-34486 in the KEV catalog underscores the immediate threat posed by this Tomcat vulnerability. The reported use of AI in its exploitation serves as a stark reminder of the evolving threat landscape and the increasing sophistication of cyber adversaries. Organizations relying on Apache Tomcat, particularly those with clustered deployments, must prioritize patching and implement robust monitoring to defend against these advanced threats.

Synthesized by Vypr AI