Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CVE-2026-34486: Apache Tomcat Tribes Unauthenticated RCE

Дата публикации: 25-08-2026 08:01:22

Apache Tomcat is an open-source Java application server that provides a robust platform for hosting Java web applications and enterprise services. The Tomcat Tribes module enables clustering functionality, allowing multiple Tomcat instances to communicate for session replication and high availability.
A recently disclosed vulnerability in the Tomcat Tribes clustering component allow an unauthenticated remote attacker to achieve remote code execution (RCE) by sending specially crafted cluster messages to an exposed Tribes receiver. The vulnerability is caused by a fail-open regression introduced during the fix for CVE-2026-29146, which allows malicious messages to bypass encryption validation and reach the deserialization stage. This vulnerability has been assigned CVE-2026-34486. This article analyzes CVE-2026-34486, the vulnerable code path, affected versions, and detection considerations.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CVE-2026-34197: Apache ActiveMQ Jolokia API Remote Code Execution010.3424-08-2026
2Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands04.7128-07-2026
3CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path07.5420-05-2026
4NetScaler CVE-2026-19490 Lets Attackers Bypass Authentication 07.3319-08-2026
5What is CVE-2026-66066? Protecting Your Rails App from Active Storage RCE07.2803-08-2026
6Oracle Security Alert Advisory - CVE-2026-35273 01011-06-2026
7CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for011.5413-08-2026
8GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability 06.9719-08-2026
9How do I fix the CVE-2026-53359 vulnerability?0608-07-2026
10Security advisory: CVE-2026-9740 and CVE-2026-11933 in Percona Server for MongoDB06.5517-06-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.47. Источник: community.hpe.com.