CISA gave you until tomorrow to patch this Tomcat bug — an AI is already hunting for it

A Chinese hacker wired DeepSeek into an autonomous attack framework and pointed it at unpatched Apache Tomcat servers, and CISA wants federal…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-34486 (CVSS 7.5) lets an attacker bypass Tomcat's EncryptInterceptor, the feature meant to encrypt traffic between cluster nodes.

The short version

CISA added it to the KEV catalog on August 5, 2026, with a patch deadline of August 7 for federal systems.

The short version

It exists because the original fix for a different Tomcat bug, CVE-2026-29146, introduced a new flaw of its own.

The short version

A Chinese-speaking actor known as knaithe (aka KnYuan) used DeepSeek inside an autonomous framework called Hermes Agent to find and hit exposed Tomcat servers.

The short version

Fixed versions: Tomcat 11.0.21, 10.1.54, and 9.0.117 — upgrade even if you already patched for the earlier bug.

Patch priority

If you run Tomcat with clustering enabled anywhere on the open internet, this goes to the top of today's list — not because the CVSS score is dramatic (7.5 isn't a 10), but because it's confirmed…

Aliteq

Read the full story

CISA gave you until tomorrow to patch this Tomcat bug — an AI is already hunting for it

Read the full story on Aliteq