Apache Tomcat disclosed CVE-2026-34486, an unauthenticated remote code execution flaw in the Tribes clustering component after a fix for CVE-2026-29146 introduced a fail-open regression in EncryptInterceptor. The earlier issue, rated Important, stemmed from the component's default use of CBC mode, which exposed it to a padding oracle attack in Tomcat 11.0.0-M1 through 11.0.18, 10.1.0-M1 through 10.1.52, and 9.0.13 through 9.0.115; Apache directed users to upgrade to 11.0.20+, 10.1.53+, or 9.0.116+ to address it. A separate low-severity advisory, CVE-2026-29129, reported that configured TLS cipher preference order was not preserved in Tomcat 11.0.16 through 11.0.18, 10.1.51 through 10.1.52, and 9.0.114 through 9.0.115.
Research published by Striga showed that the March fix for the padding oracle bug moved a call in the receive path so that attacker-controlled bytes could still be forwarded for deserialization even when decryption failed. Because Tribes accepts unauthenticated messages on its cluster receiver port and deserializes them with Java ObjectInputStream.readObject() without an ObjectInputFilter, a remote attacker could send crafted unencrypted packets and achieve code execution if suitable gadget classes were present on the classpath. Apache fixed CVE-2026-34486 in Tomcat 11.0.21, 10.1.54, and 9.0.117; public reproduction material showed exploitation against the default receiver port 4000 using a deserialization gadget chain to create /tmp/pwned in a test container.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository was published with a reproduction for CVE-2026-34486 showing how to send an unencrypted gadget payload to the Tomcat Tribes receiver and verify code execution. The repository attributed discovery and reporting to Bartlomiej Dmitruk of Striga.ai.
Apache publicly disclosed CVE-2026-29129, CVE-2026-29146, and CVE-2026-34486 in security advisories and mailing-list posts. The disclosures covered a low-severity TLS cipher order issue, the EncryptInterceptor padding oracle flaw, and the regression that enabled unauthenticated RCE in Tomcat Tribes.
Apache released Tomcat 11.0.21, 10.1.54, and 9.0.117 to fix CVE-2026-34486, an unauthenticated remote code execution flaw in Tomcat Tribes clustering. The bug was introduced by the earlier CVE-2026-29146 fix, which caused attacker-controlled undecrypted bytes to be forwarded for Java deserialization when decryption failed.
Apache released Tomcat versions 11.0.20, 10.1.53, and 9.0.116 to address CVE-2026-29146, an Important-severity padding oracle vulnerability in the Tribes EncryptInterceptor caused by default CBC mode. The issue affected Tomcat 11.0.0-M1 through 11.0.18, 10.1.0-M1 through 10.1.52, and 9.0.13 through 9.0.115.
Striga published a technical analysis of CVE-2026-34486 explaining how a one-line change in the CVE-2026-29146 fix created a fail-open path to unauthenticated deserialization and possible remote code execution on the Tribes receiver port. The write-up also identified the affected and fixed Tomcat versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcegithub.com
Open sourcelists.apache.org
Open sourcelists.apache.org
Open sourceseclists.org
Open sourcelists.apache.org
Open sourcestriga.ai
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.