# CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns

> Apache Tomcat CVE-2026-34486 is a missing encryption of sensitive data vulnerability in the Tribes EncryptInterceptor, introduced as a code regression during the fix for CVE-2026-29146 (padding oracle). The fix moved super.messageReceived() outside the try-catch block, causing any decryption failure to log the error but still forward the attacker-controlled raw bytes upstream, where ObjectInputStream.readObject() deserializes them with no class filter — enabling unauthenticated Java deserialization RCE. CISA added the CVE to its KEV catalog on August 4, 2026, confirming active exploitation. Two distinct Chinese-nexus threat clusters actively exploit this vulnerability: the SnowLight campaign (UNC5174/UNC6586 initial access brokers using GoCobaltStrike, VShell, and Sliver) targeting government infrastructure across 100+ countries, and an individual actor (knaithe/KnYuan from Zhuhai, China) using a Hermes Agent + DeepSeek autonomous AI attack framework coupled with manual Java deserialization reverse shell campaigns.

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1885
- **ID:** TL-2026-1885
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** UNC5174 (China)
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-34486, CVE-2022-26134, CVE-2025-68613, CVE-2026-21858, CVE-2026-29146, CVE-2026-3055, CVE-2026-33017, CVE-2026-39987, CVE-2026-41940

## Description

CVE-2026-34486 is an unauthenticated Java deserialization vulnerability in Apache Tomcat's Tribes cluster communication module, specifically in the EncryptInterceptor. The flaw was introduced as a regression during the remediation of CVE-2026-29146, a padding oracle vulnerability in the same interceptor (CVSS 7.5, CWE-209/CWE-642). In attempting to fix the padding oracle by switching from AES/CBC/PKCS5Padding to AES/GCM/NoPadding and restructuring the encryption manager, the fix accidentally moved the super.messageReceived(msg) call from inside the try block to outside it. The consequence: when the encryption manager throws a GeneralSecurityException (IllegalBlockSizeException with CBC padding, or AEADBadTagException with GCM), the error is logged at SEVERE level but the original attacker-controlled bytes are still forwarded up the interceptor chain. The message propagates through MessageDispatchInterceptor to GroupChannel.messageReceived(), where XByteBuffer.deserialize() calls ObjectInputStream.readObject() with no class filter applied. This enables unauthenticated remote attackers with network access to the Tribes port (default 4000) to send raw Tribes wire-protocol frames containing serialized Java objects using known gadget chains such as CommonsCollections6, which works across JDK 8 through 21. The ysoserial CommonsCollections6 chain uses HashSet as the deserialization entry point, routing through TiedMapEntry.hashCode() to LazyMap.get() which invokes a ChainedTransformer that executes arbitrary commands via Runtime.exec().

Two distinct Chinese-nexus threat clusters are actively exploiting this CVE in overlapping campaigns. The SnowLight campaign, tracked by SOCRadar's Threat Research Unit and attributed to Google Threat Intelligence Group initial access brokers UNC5174 and UNC6586, operated over at least a six-week window, scanning over 9,990 hostnames across 104 country-code TLDs and successfully breaching 107 endpoints. CVE-2026-34486 was one of nine weaponized CVEs in their arsenal, alongside exploits targeting Microsoft Exchange (ProxyShell), cPanel/WHM (CVE-2026-41940 — 16 root-level takeovers), Atlassian Confluence (CVE-2022-26134 — 80 servers), and F5 BIG-IP. Over 85% of reconnaissance listings targeted government infrastructure (.gov.*, .go.id) across Taiwan, Colombia, Brazil, Indonesia, Nigeria, the Philippines, and 90+ other jurisdictions. The operators used GoCobaltStrike, a cracked Chinese-language Go reimplementation of Cobalt Strike authored by the handle "星落" (Xing Luo/Starfall), with all 22 GoCobaltStrike logins originating from a single China Unicom IP address in Tianjin with UTC+8 timezone alignment. Post-exploitation tooling included SNOWLIGHT (dnsloger), a fileless dropper using memfd_create + fexecve to load payloads in memory while spoofing the process name as [kworker/0:2] to impersonate kernel threads; VShell, an open-source Go RAT with WebSocket C2 over port 8443; Sliver C2 implants with mTLS, WireGuard, and HTTPS protocols; and Neo-reGeorg reverse tunnels layered over JSP web shells. The SNOWLIGHT family has been tracked by GTIG since 2024, with early samples linked to loaders dropping VShell as early as November 2024.

Separately, Palo Alto Networks Unit 42 documented an individual Chinese-speaking threat actor (aliases: knaithe, KnYuan) based in Zhuhai, China, who conducted manual exploitation campaigns targeting nine Apache Tomcat servers with Java deserialization reverse shells. This actor also built an autonomous AI-driven attack framework pairing Hermes Agent (NousResearch orchestration framework) with DeepSeek as the reasoning engine, integrating custom skills for FOFA internet asset enumeration (fofaapi.py), web-terminal exploitation, and LLM jailbreaking ("godmode"). The actor operated via Telegram C2, maintained an automated vulnerability intelligence pipeline called "1DayNews" aggregating RCE disclosures from 17 sources, and created a FofaMap-Platinum-Full-Expert MCP server exposing natural-language-to-FOFA query translation. The autonomous attack cycle attempted Langflow (CVE-2026-33017, CVSS 9.8) and n8n (CVE-2026-21858/CVE-2025-68613, CVSS 10.0/9.9) before those efforts failed due to authentication requirements, then shifted to manual exploitation of CVE-2026-34486, CVE-2026-3055 (Citrix NetScaler — data exfiltrated from 3 organizations via NSC_AAAC= cookie hijacking), CVE-2026-39987 (Marimo Notebook — 11 instances compromised), and CVE-2026-33824 (Windows IKE VPN — 3 endpoints with reverse shell callbacks). The actor's operation was exposed when Hermes Agent, responding to a Telegram command, started an HTTP server from the home directory (/home/worker) instead of an isolated staging directory, exposing API keys, exploit scripts, target lists, bash history, and session logs.

Affected versions are Apache Tomcat 11.0.20, 10.1.53, and 9.0.116. Fixed versions are 11.0.21, 10.1.54, and 9.0.117. Red Hat issued 13 RHSA errata covering RHEL 6-10 and JBoss Web Server. The vulnerability has a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) per CISA-ADP and Red Hat assessments, though exploit PoCs and some sources characterize it as RCE (the deserialization can yield code execution when gadget libraries such as commons-collections-3.1.jar or Spring dependencies are on the classpath). CISA SSVC assessment rates exploitation as active, automatable as yes, and technical impact as total.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1106 Native API
- T1543 Create or Modify System Process
- T1053 Scheduled Task/Job
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1055 Process Injection
- T1528 Steal Application Access Token
- T1046 Network Service Discovery
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1095 Non-Application Layer Protocol
- T1572 Protocol Tunneling
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1595 Active Scanning

## Sources

- [CISA Known Exploited Vulnerabilities Catalog — CVE-2026-34486](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486)
- [NVD Detail — CVE-2026-34486](https://nvd.nist.gov/vuln/detail/CVE-2026-34486)
- [Apache Tomcat Mailing List Advisory](https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly)
- [Technical Analysis — Tomcat EncryptInterceptor Fails Open](https://nefariousplan.com/posts/tomcat-encryptinterceptor-fails-open)
- [Striga AI Research — Tomcat Tribes Unauthenticated RCE](https://www.striga.ai/research/tomcat-tribes-unauth-rce)
- [GitHub PoC — CVE-2026-34486](https://github.com/striga-ai/CVE-2026-34486)
- [Video PoC — Exploiting RCE in Apache Tomcat 10.1.53](https://www.karczewski.io/blog/exploiting-rce-in-apache-tomcat-10-1-53-cve-2026-34486-video-poc/)
- [SOCRadar — SnowLight: China-Nexus Campaign Against Government Infrastructure](https://socradar.io/blog/snowlight-government-chinese-campaign/)
- [Unit 42 — Autonomous AI Cyber Attack Campaign Using Hermes Agent + DeepSeek](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)
- [Sysdig — UNC5174 Chinese Threat Actor VShell Analysis](https://sysdig.com/blog/unc5174-chinese-threat-actor-vshell)
- [Cyber Security News — Apache Tomcat Encryption Vulnerability](https://cybersecuritynews.com/apache-tomcat-encryption-vulnerability/)
- [itnerd.blog — SOCRadar Uncovers SnowLight Campaign](https://itnerd.blog/2026/08/03/socradar-uncovers-new-china-nexus-campaign-snowlight-against-government-infrastructure/)
- [Red Hat CVE — CVE-2026-34486](https://access.redhat.com/security/cve/CVE-2026-34486)
- [Vicarius — CVE-2026-34486 Detection Script](https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1885
