CISA says attackers are exploiting a newly tracked Apache Tomcat vulnerability and has ordered federal agencies to apply mitigations within three days. The flaw, CVE-2026-34486, is a high-severity issue caused by an incomplete fix for CVE-2026-29146; Palo Alto Networks Unit 42 said a Chinese-speaking threat actor manually exploited it on nine Tomcat servers to try to plant reverse shells, which give attackers remote command access.
Why it matters: Organizations running Apache Tomcat should not assume earlier fixes were enough if they patched only the original issue. Review whether systems are exposed, apply the latest fixes, and check for signs of web shells or reverse-shell persistence.
Ionut Ilascu
2026.08.05
100% relevant
This article establishes a new tracked story because the underlying event is active exploitation of a different Apache Tomcat CVE, distinct from the previously tracked Tomcat flaw CVE-2025-24813.
← Back to all stories