Threat reportVulnerabilityTL-2026-1885

CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns

highACTIVE

CVE-2026-34486 (TL-2026-1885), also tracked as SnowLight Campaign, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-08-05. It is attributed to UNC5174 (China) with high confidence, affects Apache Tomcat, references 9 CVEs (CVE-2026-34486, CVE-2022-26134, CVE-2025-68613), maps to 18 MITRE ATT&CK techniques (T1027, T1036, T1046), and is covered by 9 detection rules and 29 indicators of compromise.

CVSS
7.5/10High
CVEs
9Referenced vulnerabilities
Techniques
18MITRE ATT&CK
Actors
2UNC5174
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1885

Threat ID
TL-2026-1885
Also known as
SnowLight Campaign, UNC5174, UNC6586, knaithe operation
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
UNC5174, UNC6586
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, technology, telecoms, academic, energy
Target regions
East Asia, 005 - South America, Southeast Asia, Africa, South Asia
Detection rules
9
Indicators of compromise
29

Malware and tooling in CVE-2026-34486

Malware and tooling: Neo-reGeorg - S1189, SNOWLIGHT, VShell, GoCobaltStrike, Hermes Agent, Neo-reGeorg, Sliver - S0633

How CVE-2026-34486 works

Apache Tomcat CVE-2026-34486 is a missing encryption of sensitive data vulnerability in the Tribes EncryptInterceptor, introduced as a code regression during the fix for CVE-2026-29146 (padding oracle). The fix moved super.messageReceived() outside the try-catch block, causing any decryption failure to log the error but still forward the attacker-controlled raw bytes upstream, where ObjectInputStream.readObject() deserializes them with no class filter — enabling unauthenticated Java deserialization RCE. CISA added the CVE to its KEV catalog on August 4, 2026, confirming active exploitation. Two distinct Chinese-nexus threat clusters actively exploit this vulnerability: the SnowLight campaign (UNC5174/UNC6586 initial access brokers using GoCobaltStrike, VShell, and Sliver) targeting government infrastructure across 100+ countries, and an individual actor (knaithe/KnYuan from Zhuhai, China) using a Hermes Agent + DeepSeek autonomous AI attack framework coupled with manual Java deserialization reverse shell campaigns.

CVE-2026-34486 is an unauthenticated Java deserialization vulnerability in Apache Tomcat's Tribes cluster communication module, specifically in the EncryptInterceptor. The flaw was introduced as a regression during the remediation of CVE-2026-29146, a padding oracle vulnerability in the same interceptor (CVSS 7.5, CWE-209/CWE-642). In attempting to fix the padding oracle by switching from AES/CBC/PKCS5Padding to AES/GCM/NoPadding and restructuring the encryption manager, the fix accidentally moved the super.messageReceived(msg) call from inside the try block to outside it. The consequence: when the encryption manager throws a GeneralSecurityException (IllegalBlockSizeException with CBC padding, or AEADBadTagException with GCM), the error is logged at SEVERE level but the original attacker-controlled bytes are still forwarded up the interceptor chain. The message propagates through MessageDispatchInterceptor to GroupChannel.messageReceived(), where XByteBuffer.deserialize() calls ObjectInputStream.readObject() with no class filter applied. This enables unauthenticated remote attackers with network access to the Tribes port (default 4000) to send raw Tribes wire-protocol frames containing serialized Java objects using known gadget chains such as CommonsCollections6, which works across JDK 8 through 21. The ysoserial CommonsCollections6 chain uses HashSet as the deserialization entry point, routing through TiedMapEntry.hashCode() to LazyMap.get() which invokes a ChainedTransformer that executes arbitrary commands via Runtime.exec().

Two distinct Chinese-nexus threat clusters are actively exploiting this CVE in overlapping campaigns. The SnowLight campaign, tracked by SOCRadar's Threat Research Unit and attributed to Google Threat Intelligence Group initial access brokers UNC5174 and UNC6586, operated over at least a six-week window, scanning over 9,990 hostnames across 104 country-code TLDs and successfully breaching 107 endpoints. CVE-2026-34486 was one of nine weaponized CVEs in their arsenal, alongside exploits targeting Microsoft Exchange (ProxyShell), cPanel/WHM (CVE-2026-41940 — 16 root-level takeovers), Atlassian Confluence (CVE-2022-26134 — 80 servers), and F5 BIG-IP. Over 85% of reconnaissance listings targeted government infrastructure (.gov.*, .go.id) across Taiwan, Colombia, Brazil, Indonesia, Nigeria, the Philippines, and 90+ other jurisdictions. The operators used GoCobaltStrike, a cracked Chinese-language Go reimplementation of Cobalt Strike authored by the handle "星落" (Xing Luo/Starfall), with all 22 GoCobaltStrike logins originating from a single China Unicom IP address in Tianjin with UTC+8 timezone alignment. Post-exploitation tooling included SNOWLIGHT (dnsloger), a fileless dropper using memfd_create + fexecve to load payloads in memory while spoofing the process name as [kworker/0:2] to impersonate kernel threads; VShell, an open-source Go RAT with WebSocket C2 over port 8443; Sliver C2 implants with mTLS, WireGuard, and HTTPS protocols; and Neo-reGeorg reverse tunnels layered over JSP web shells. The SNOWLIGHT family has been tracked by GTIG since 2024, with early samples linked to loaders dropping VShell as early as November 2024.

Separately, Palo Alto Networks Unit 42 documented an individual Chinese-speaking threat actor (aliases: knaithe, KnYuan) based in Zhuhai, China, who conducted manual exploitation campaigns targeting nine Apache Tomcat servers with Java deserialization reverse shells. This actor also built an autonomous AI-driven attack framework pairing Hermes Agent (NousResearch orchestration framework) with DeepSeek as the reasoning engine, integrating custom skills for FOFA internet asset enumeration (fofaapi.py), web-terminal exploitation, and LLM jailbreaking ("godmode"). The actor operated via Telegram C2, maintained an automated vulnerability intelligence pipeline called "1DayNews" aggregating RCE disclosures from 17 sources, and created a FofaMap-Platinum-Full-Expert MCP server exposing natural-language-to-FOFA query translation. The autonomous attack cycle attempted Langflow (CVE-2026-33017, CVSS 9.8) and n8n (CVE-2026-21858/CVE-2025-68613, CVSS 10.0/9.9) before those efforts failed due to authentication requirements, then shifted to manual exploitation of CVE-2026-34486, CVE-2026-3055 (Citrix NetScaler — data exfiltrated from 3 organizations via NSC_AAAC= cookie hijacking), CVE-2026-39987 (Marimo Notebook — 11 instances compromised), and CVE-2026-33824 (Windows IKE VPN — 3 endpoints with reverse shell callbacks). The actor's operation was exposed when Hermes Agent, responding to a Telegram command, started an HTTP server from the home directory (/home/worker) instead of an isolated staging directory, exposing API keys, exploit scripts, target lists, bash history, and session logs.

Affected versions are Apache Tomcat 11.0.20, 10.1.53, and 9.0.116. Fixed versions are 11.0.21, 10.1.54, and 9.0.117. Red Hat issued 13 RHSA errata covering RHEL 6-10 and JBoss Web Server. The vulnerability has a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) per CISA-ADP and Red Hat assessments, though exploit PoCs and some sources characterize it as RCE (the deserialization can yield code execution when gadget libraries such as commons-collections-3.1.jar or Spring dependencies are on the classpath). CISA SSVC assessment rates exploitation as active, automatable as yes, and technical impact as total.

MITRE ATT&CK techniques used in TL-2026-1885

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information

Discovery

T1046 Network Service Discovery

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process

Command and Control

T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1572 Protocol Tunneling; T1573 Encrypted Channel

Execution

T1106 Native API; T1203 Exploitation for Client Execution

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1528 Steal Application Access Token

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in CVE-2026-34486

  • Apache — Tomcat
    Vulnerable versions: 9.0.116; 10.1.53; 11.0.20
    Fixed in: 9.0.117; 10.1.54; 11.0.21
  • Red Hat — Enterprise Linux
    Vulnerable versions: RHEL 6 ELS; RHEL 7 ELS; RHEL 8; RHEL 9; RHEL 10
    Fixed in: Multiple RHSA errata published
  • Red Hat — JBoss Web Server
    Vulnerable versions: 5.0; 7.0.0
    Fixed in: Per RHSA advisory

Remediation for CVE-2026-34486

Patches

  • Upgrade Tomcat 11.0.x to 11.0.21
  • Upgrade Tomcat 10.1.x to 10.1.54
  • Upgrade Tomcat 9.0.x to 9.0.117
  • Apply Red Hat RHSA errata (RHSA-2026:36787-36879, 37136-37137, 38505, 39188-39189) for RHEL packaged Tomcat

Immediate actions

  • Upgrade Apache Tomcat to 11.0.21, 10.1.54, or 9.0.117 immediately
  • Restrict network access to Tribes cluster port (default 4000) to only trusted cluster nodes
  • Review Tomcat logs for SEVERE 'Failed to decrypt message' entries with IllegalBlockSizeException or AEADBadTagException on cluster nodes
  • Audit exposed Tomcat servers for unexpected outbound connections and unauthorized file changes

Workarounds

  • If patching is delayed, restrict Tribes port 4000 to trusted IPs only via iptables/firewalld
  • Set -Dorg.apache.catalina.tribes.io.ObjectInputStream-filter=REJECT ALL or configure a serialization filter via conf/catalina.properties
  • Disable clustering if not required for operations
  • Monitor for SEVERE Tomcat log lines containing 'Failed to decrypt message' as potential exploitation indicators

Longer-term hardening

  • Remove unnecessary gadget libraries (commons-collections, etc.) from CATALINA_HOME/lib/
  • Deploy EDR with behavioral detection for fileless execution, memfd_create syscall monitoring, and process name spoofing ([kworker/*] anomalies)
  • Implement WebSocket C2 traffic detection rules for uncommon WebSocket upgrades on non-browser ports
  • Apply network segmentation isolating cluster communication to private VLANs

CVEs associated with CVE-2026-34486

CVE-2026-34486, CVE-2022-26134, CVE-2025-68613, CVE-2026-21858, CVE-2026-29146, CVE-2026-3055, CVE-2026-33017, CVE-2026-39987, CVE-2026-41940

Weaknesses (CWE) in CVE-2026-34486

CWE-311, CWE-807

Timeline of CVE-2026-34486

  • First SNOWLIGHT sample (dnsloger) observed on VirusTotal, dropping VShell payload — earliest known precursor activity from UNC5174/UNC6586 initial access brokers
  • Sysdig Threat Research Team publishes analysis of UNC5174 campaign using SNOWLIGHT + VShell fileless malware with WebSocket C2 over port 8443, linked to Chinese initial access brokers
  • Apache Software Foundation discloses CVE-2026-34486 and releases patched versions 11.0.21, 10.1.54, and 9.0.117. NVD publishes initial CVSS 7.5 scoring. The vulnerability is a regression from the CVE-2026-29146 padding oracle fix
  • Striga AI Research publishes full technical writeup of the unauthenticated RCE vulnerability with bytecode-level analysis of the EncryptInterceptor regression. nefariousplan.com publishes detailed PoC with raw Tribes wire protocol frame construction
  • Video PoC demonstrating exploitation of CVE-2026-34486 on Apache Tomcat 10.1.53 published, demonstrating CommonsCollections6 gadget chain achieving RCE via ysoserial-generated payload
  • Actor knaithe/KnYuan runs autonomous AI attack cycle using Hermes Agent + DeepSeek, targeting Langflow, n8n, and other perimeter software. Operation exposed when the agent starts HTTP server from /home/worker directory. Actor also conducts manual CVE-2026-34486 exploitation against 9 Apache Tomcat servers
  • Vicarius/vsociety user bcena publishes CVE-2026-34486 detection script for identifying vulnerable Tomcat EncryptInterceptor configurations
  • SOCRadar Threat Research Unit publishes full analysis of the SnowLight campaign, uncovering an exposed adversary staging server containing weaponized exploits for 9 CVEs including CVE-2026-34486, documenting 107 breached endpoints across 100+ countries
  • CISA adds CVE-2026-34486 to the Known Exploited Vulnerabilities (KEV) catalog with remediation deadline of August 7, 2026. CISA-ADP SSVC assessment updates exploitation status from 'none' to 'active' and technical impact to 'total'. Unit 42 publishes independent report on knaithe/KnYuan AI-assisted attack campaign
  • Cyber Security News publishes coverage of CISA KEV addition and details of the Apache Tomcat EncryptInterceptor bypass affecting clustered deployments

Sources cited for CVE-2026-34486

Detection coverage for TL-2026-1885

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1885 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats