Threat reportVulnerabilityTL-2026-1885
CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns
CVE-2026-34486 (TL-2026-1885), also tracked as SnowLight Campaign, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-08-05. It is attributed to UNC5174 (China) with high confidence, affects Apache Tomcat, references 9 CVEs (CVE-2026-34486, CVE-2022-26134, CVE-2025-68613), maps to 18 MITRE ATT&CK techniques (T1027, T1036, T1046), and is covered by 9 detection rules and 29 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 9Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 2UNC5174
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-1885
- Threat ID
- TL-2026-1885
- Also known as
- SnowLight Campaign, UNC5174, UNC6586, knaithe operation
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- UNC5174, UNC6586
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, technology, telecoms, academic, energy
- Target regions
- East Asia, 005 - South America, Southeast Asia, Africa, South Asia
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in CVE-2026-34486
Malware and tooling: Neo-reGeorg - S1189, SNOWLIGHT, VShell, GoCobaltStrike, Hermes Agent, Neo-reGeorg, Sliver - S0633
How CVE-2026-34486 works
Apache Tomcat CVE-2026-34486 is a missing encryption of sensitive data vulnerability in the Tribes EncryptInterceptor, introduced as a code regression during the fix for CVE-2026-29146 (padding oracle). The fix moved super.messageReceived() outside the try-catch block, causing any decryption failure to log the error but still forward the attacker-controlled raw bytes upstream, where ObjectInputStream.readObject() deserializes them with no class filter — enabling unauthenticated Java deserialization RCE. CISA added the CVE to its KEV catalog on August 4, 2026, confirming active exploitation. Two distinct Chinese-nexus threat clusters actively exploit this vulnerability: the SnowLight campaign (UNC5174/UNC6586 initial access brokers using GoCobaltStrike, VShell, and Sliver) targeting government infrastructure across 100+ countries, and an individual actor (knaithe/KnYuan from Zhuhai, China) using a Hermes Agent + DeepSeek autonomous AI attack framework coupled with manual Java deserialization reverse shell campaigns.
CVE-2026-34486 is an unauthenticated Java deserialization vulnerability in Apache Tomcat's Tribes cluster communication module, specifically in the EncryptInterceptor. The flaw was introduced as a regression during the remediation of CVE-2026-29146, a padding oracle vulnerability in the same interceptor (CVSS 7.5, CWE-209/CWE-642). In attempting to fix the padding oracle by switching from AES/CBC/PKCS5Padding to AES/GCM/NoPadding and restructuring the encryption manager, the fix accidentally moved the super.messageReceived(msg) call from inside the try block to outside it. The consequence: when the encryption manager throws a GeneralSecurityException (IllegalBlockSizeException with CBC padding, or AEADBadTagException with GCM), the error is logged at SEVERE level but the original attacker-controlled bytes are still forwarded up the interceptor chain. The message propagates through MessageDispatchInterceptor to GroupChannel.messageReceived(), where XByteBuffer.deserialize() calls ObjectInputStream.readObject() with no class filter applied. This enables unauthenticated remote attackers with network access to the Tribes port (default 4000) to send raw Tribes wire-protocol frames containing serialized Java objects using known gadget chains such as CommonsCollections6, which works across JDK 8 through 21. The ysoserial CommonsCollections6 chain uses HashSet as the deserialization entry point, routing through TiedMapEntry.hashCode() to LazyMap.get() which invokes a ChainedTransformer that executes arbitrary commands via Runtime.exec().
Two distinct Chinese-nexus threat clusters are actively exploiting this CVE in overlapping campaigns. The SnowLight campaign, tracked by SOCRadar's Threat Research Unit and attributed to Google Threat Intelligence Group initial access brokers UNC5174 and UNC6586, operated over at least a six-week window, scanning over 9,990 hostnames across 104 country-code TLDs and successfully breaching 107 endpoints. CVE-2026-34486 was one of nine weaponized CVEs in their arsenal, alongside exploits targeting Microsoft Exchange (ProxyShell), cPanel/WHM (CVE-2026-41940 — 16 root-level takeovers), Atlassian Confluence (CVE-2022-26134 — 80 servers), and F5 BIG-IP. Over 85% of reconnaissance listings targeted government infrastructure (.gov.*, .go.id) across Taiwan, Colombia, Brazil, Indonesia, Nigeria, the Philippines, and 90+ other jurisdictions. The operators used GoCobaltStrike, a cracked Chinese-language Go reimplementation of Cobalt Strike authored by the handle "星落" (Xing Luo/Starfall), with all 22 GoCobaltStrike logins originating from a single China Unicom IP address in Tianjin with UTC+8 timezone alignment. Post-exploitation tooling included SNOWLIGHT (dnsloger), a fileless dropper using memfd_create + fexecve to load payloads in memory while spoofing the process name as [kworker/0:2] to impersonate kernel threads; VShell, an open-source Go RAT with WebSocket C2 over port 8443; Sliver C2 implants with mTLS, WireGuard, and HTTPS protocols; and Neo-reGeorg reverse tunnels layered over JSP web shells. The SNOWLIGHT family has been tracked by GTIG since 2024, with early samples linked to loaders dropping VShell as early as November 2024.
Separately, Palo Alto Networks Unit 42 documented an individual Chinese-speaking threat actor (aliases: knaithe, KnYuan) based in Zhuhai, China, who conducted manual exploitation campaigns targeting nine Apache Tomcat servers with Java deserialization reverse shells. This actor also built an autonomous AI-driven attack framework pairing Hermes Agent (NousResearch orchestration framework) with DeepSeek as the reasoning engine, integrating custom skills for FOFA internet asset enumeration (fofaapi.py), web-terminal exploitation, and LLM jailbreaking ("godmode"). The actor operated via Telegram C2, maintained an automated vulnerability intelligence pipeline called "1DayNews" aggregating RCE disclosures from 17 sources, and created a FofaMap-Platinum-Full-Expert MCP server exposing natural-language-to-FOFA query translation. The autonomous attack cycle attempted Langflow (CVE-2026-33017, CVSS 9.8) and n8n (CVE-2026-21858/CVE-2025-68613, CVSS 10.0/9.9) before those efforts failed due to authentication requirements, then shifted to manual exploitation of CVE-2026-34486, CVE-2026-3055 (Citrix NetScaler — data exfiltrated from 3 organizations via NSC_AAAC= cookie hijacking), CVE-2026-39987 (Marimo Notebook — 11 instances compromised), and CVE-2026-33824 (Windows IKE VPN — 3 endpoints with reverse shell callbacks). The actor's operation was exposed when Hermes Agent, responding to a Telegram command, started an HTTP server from the home directory (/home/worker) instead of an isolated staging directory, exposing API keys, exploit scripts, target lists, bash history, and session logs.
Affected versions are Apache Tomcat 11.0.20, 10.1.53, and 9.0.116. Fixed versions are 11.0.21, 10.1.54, and 9.0.117. Red Hat issued 13 RHSA errata covering RHEL 6-10 and JBoss Web Server. The vulnerability has a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) per CISA-ADP and Red Hat assessments, though exploit PoCs and some sources characterize it as RCE (the deserialization can yield code execution when gadget libraries such as commons-collections-3.1.jar or Spring dependencies are on the classpath). CISA SSVC assessment rates exploitation as active, automatable as yes, and technical impact as total.
MITRE ATT&CK techniques used in TL-2026-1885
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information
Discovery
T1046 Network Service Discovery
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process
Command and Control
T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1572 Protocol Tunneling; T1573 Encrypted Channel
Execution
T1106 Native API; T1203 Exploitation for Client Execution
Initial Access
T1190 Exploit Public-Facing Application
Credential Access
T1528 Steal Application Access Token
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in CVE-2026-34486
- Apache — Tomcat
Vulnerable versions: 9.0.116; 10.1.53; 11.0.20
Fixed in: 9.0.117; 10.1.54; 11.0.21 - Red Hat — Enterprise Linux
Vulnerable versions: RHEL 6 ELS; RHEL 7 ELS; RHEL 8; RHEL 9; RHEL 10
Fixed in: Multiple RHSA errata published - Red Hat — JBoss Web Server
Vulnerable versions: 5.0; 7.0.0
Fixed in: Per RHSA advisory
Remediation for CVE-2026-34486
Patches
- Upgrade Tomcat 11.0.x to 11.0.21
- Upgrade Tomcat 10.1.x to 10.1.54
- Upgrade Tomcat 9.0.x to 9.0.117
- Apply Red Hat RHSA errata (RHSA-2026:36787-36879, 37136-37137, 38505, 39188-39189) for RHEL packaged Tomcat
Immediate actions
- Upgrade Apache Tomcat to 11.0.21, 10.1.54, or 9.0.117 immediately
- Restrict network access to Tribes cluster port (default 4000) to only trusted cluster nodes
- Review Tomcat logs for SEVERE 'Failed to decrypt message' entries with IllegalBlockSizeException or AEADBadTagException on cluster nodes
- Audit exposed Tomcat servers for unexpected outbound connections and unauthorized file changes
Workarounds
- If patching is delayed, restrict Tribes port 4000 to trusted IPs only via iptables/firewalld
- Set -Dorg.apache.catalina.tribes.io.ObjectInputStream-filter=REJECT ALL or configure a serialization filter via conf/catalina.properties
- Disable clustering if not required for operations
- Monitor for SEVERE Tomcat log lines containing 'Failed to decrypt message' as potential exploitation indicators
Longer-term hardening
- Remove unnecessary gadget libraries (commons-collections, etc.) from CATALINA_HOME/lib/
- Deploy EDR with behavioral detection for fileless execution, memfd_create syscall monitoring, and process name spoofing ([kworker/*] anomalies)
- Implement WebSocket C2 traffic detection rules for uncommon WebSocket upgrades on non-browser ports
- Apply network segmentation isolating cluster communication to private VLANs
CVEs associated with CVE-2026-34486
CVE-2026-34486, CVE-2022-26134, CVE-2025-68613, CVE-2026-21858, CVE-2026-29146, CVE-2026-3055, CVE-2026-33017, CVE-2026-39987, CVE-2026-41940
Weaknesses (CWE) in CVE-2026-34486
Timeline of CVE-2026-34486
- First SNOWLIGHT sample (dnsloger) observed on VirusTotal, dropping VShell payload — earliest known precursor activity from UNC5174/UNC6586 initial access brokers
- Sysdig Threat Research Team publishes analysis of UNC5174 campaign using SNOWLIGHT + VShell fileless malware with WebSocket C2 over port 8443, linked to Chinese initial access brokers
- Apache Software Foundation discloses CVE-2026-34486 and releases patched versions 11.0.21, 10.1.54, and 9.0.117. NVD publishes initial CVSS 7.5 scoring. The vulnerability is a regression from the CVE-2026-29146 padding oracle fix
- Striga AI Research publishes full technical writeup of the unauthenticated RCE vulnerability with bytecode-level analysis of the EncryptInterceptor regression. nefariousplan.com publishes detailed PoC with raw Tribes wire protocol frame construction
- Video PoC demonstrating exploitation of CVE-2026-34486 on Apache Tomcat 10.1.53 published, demonstrating CommonsCollections6 gadget chain achieving RCE via ysoserial-generated payload
- Actor knaithe/KnYuan runs autonomous AI attack cycle using Hermes Agent + DeepSeek, targeting Langflow, n8n, and other perimeter software. Operation exposed when the agent starts HTTP server from /home/worker directory. Actor also conducts manual CVE-2026-34486 exploitation against 9 Apache Tomcat servers
- Vicarius/vsociety user bcena publishes CVE-2026-34486 detection script for identifying vulnerable Tomcat EncryptInterceptor configurations
- SOCRadar Threat Research Unit publishes full analysis of the SnowLight campaign, uncovering an exposed adversary staging server containing weaponized exploits for 9 CVEs including CVE-2026-34486, documenting 107 breached endpoints across 100+ countries
- CISA adds CVE-2026-34486 to the Known Exploited Vulnerabilities (KEV) catalog with remediation deadline of August 7, 2026. CISA-ADP SSVC assessment updates exploitation status from 'none' to 'active' and technical impact to 'total'. Unit 42 publishes independent report on knaithe/KnYuan AI-assisted attack campaign
- Cyber Security News publishes coverage of CISA KEV addition and details of the Apache Tomcat EncryptInterceptor bypass affecting clustered deployments
Sources cited for CVE-2026-34486
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-34486
- NVD Detail — CVE-2026-34486
- Apache Tomcat Mailing List Advisory
- Technical Analysis — Tomcat EncryptInterceptor Fails Open
- Striga AI Research — Tomcat Tribes Unauthenticated RCE
- GitHub PoC — CVE-2026-34486
- Video PoC — Exploiting RCE in Apache Tomcat 10.1.53
- SOCRadar — SnowLight: China-Nexus Campaign Against Government Infrastructure
- Unit 42 — Autonomous AI Cyber Attack Campaign Using Hermes Agent + DeepSeek
- Sysdig — UNC5174 Chinese Threat Actor VShell Analysis
- Cyber Security News — Apache Tomcat Encryption Vulnerability
- itnerd.blog — SOCRadar Uncovers SnowLight Campaign
- Red Hat CVE — CVE-2026-34486
- Vicarius — CVE-2026-34486 Detection Script
Detection coverage for TL-2026-1885
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1885 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.