View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA Warns Apache Tomcat CVE-2026-34486 Is Under Active Exploitation

๐Ÿšจ ACTIVE EXPLOITATION

  • UPDATE: CISA Warns Apache Tomcat CVE-2026-34486 Is Under Active Exploitation CVE-2026-34486 CISA added an actively exploited Apache Tomcat encryption flaw to its KEV catalog.

    • Apache Tomcat deployments using clustered communications are affected, especially internet-facing servers.
    • Tomcat 11.0.20, 10.1.53, and 9.0.116 contain CVE-2026-34486.
    • Crafted messages bypass the EncryptInterceptor and expose cluster traffic to unencrypted or improperly encrypted communication.
    • Unit 42 observed a Chinese-speaking threat actor attempting Java deserialization-based reverse shells against vulnerable servers. ๐Ÿ“„ Source: cisa.gov ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • QuickFox Supply-Chain Attack Delivered FDMTP via Trojanized Windows Installers A QuickFox supply-chain attack delivered the FDMTP backdoor through trojanized Windows installers.

    • Windows users of QuickFox, a VPN and network acceleration tool popular with overseas Chinese users, were targeted.
    • QuickFox version 3.0.51.0 was the earliest affected release; version 3.59.6 removed the malicious components.
    • A modified Electron renderer HTML file downloaded an obfuscated JavaScript loader from cdns3.51quickfox[.]cn.
    • The loader fingerprinted endpoints, checked running processes, and used DLL side-loading to deploy FDMTP; later payloads stored the implant in encrypted update.bin files. ๐Ÿ“„ Source: fortinet.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-18898 โ€” CVSS 7.4 โ€” UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflowA security flaw has...
  • CVE-2026-18901 โ€” CVSS 7.3 โ€” H3C NX15 Web API esps service.add routineA security vulnerability has been de...
  • CVE-2026-18900 โ€” CVSS 7.3 โ€” H3C NX15 Backend RPC esps file.exec os command injectionA weakness has been i...

๐Ÿ“‹ ADVISORIES

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check