CISA adds exploited Apache Tomcat flaw CVE-2026-34486 to KEV after reverse-shell attack attempts

CISA says attackers are exploiting a newly tracked Apache Tomcat vulnerability and has ordered federal agencies to apply mitigations within three days. The flaw, CVE-2026-34486, is a high-severity issue caused by an incomplete fix for CVE-2026-29146; Palo Alto Networks Unit 42 said a Chinese-speaking threat actor manually exploited it on nine Tomcat servers to try to plant reverse shells, which give attackers remote command access.
Why it matters: Organizations running Apache Tomcat should not assume earlier fixes were enough if they patched only the original issue. Review whether systems are exposed, apply the latest fixes, and check for signs of web shells or reverse-shell persistence.

Sources

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Ionut Ilascu 2026.08.05 100% relevant
This article establishes a new tracked story because the underlying event is active exploitation of a different Apache Tomcat CVE, distinct from the previously tracked Tomcat flaw CVE-2025-24813.
← Back to all stories