{"id":12028,"date":"2026-08-05T11:49:14","date_gmt":"2026-08-05T17:49:14","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/"},"modified":"2026-09-29T15:59:28","modified_gmt":"2026-09-29T21:59:28","slug":"alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/","title":{"rendered":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Apache Tomcat 11.x \u2013 versions prior to 11.0.21<\/li>\n\n\n\n<li>Apache Tomcat 10.x \u2013 versions prior to 10.1.54<\/li>\n\n\n\n<li>Apache Tomcat 9.x \u2013 versions prior to 9.0.117<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged in AI-enabled campaigns to distribute the SNOWLIGHT loader. Patches were published in April 2026 and apply to the 9.x, 10.x, and 11.x branches.<\/p>\n\n<p class=\"wp-block-paragraph\">Apache Tomcat is one of the most widely used Java application servers in the world, broadly deployed in enterprise environments, development platforms, and web services to host applications based on Java Servlets and JSP. On August 5, 2026, CISA added CVE\u20112026\u201134486 (CVSS: 7.5 \u2013 High) to its Known Exploited Vulnerabilities (KEV) catalog, confirming evidence of real-world active exploitation. The vulnerability, fixed by Apache in April 2026, is being actively leveraged by multiple threat actors, including automated AI-enabled campaigns, to distribute the SNOWLIGHT loader and gain initial access to compromised environments.<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE\u20112026\u201134486 \u2013 Missing Encryption of Sensitive Data in EncryptInterceptor (CVSS: 7.5 \u2013 High)<\/strong><\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">The flaw resides in the inter\u2011node clustering component of Apache Tomcat. The EncryptInterceptor is the mechanism responsible for encrypting the messages exchanged between nodes of a Tomcat cluster using a pre-shared key. A missing encryption of sensitive data vulnerability allows bypassing this component, exposing inter\u2011node traffic and allowing an attacker to intercept, manipulate, or inject messages in the communication between cluster nodes.<\/p>\n\n<p class=\"wp-block-paragraph\">In practice, the documented active exploitation uses this vector to introduce the <strong>SNOWLIGHT<\/strong> loader, an initial access component that facilitates the download and execution of additional payloads on the compromised system, enabling persistence and lateral movement within the affected environment. The campaign has been attributed to actors employing AI-enabled autonomous hacking techniques, indicating exploitation capabilities at a scale and speed superior to traditional manual campaigns.<\/p>\n\n<p class=\"wp-block-paragraph\">Initially, Apache Tomcat fixed in April 2026 the vulnerability <strong>CVE-2026-29146<\/strong>; you can find information about it in our bulletin:<\/p>\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-beacon-lab wp-block-embed-beacon-lab\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"0xQ5Zr2pnp\"><a href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/\">Alerta 2026-35 Vulnerabilidades Cr\u00edticas en Apache Tomcat y una de ellas afecta K8s<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"\u201cAlerta 2026-35 Vulnerabilidades Cr\u00edticas en Apache Tomcat y una de ellas afecta K8s\u201d \u2014 Beacon Lab\" src=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-35-critical-vulnerabilities-in-apache-tomcat-and-one-of-them-affects-k8s\/embed\/#?secret=Vv9XYnJSbv#?secret=0xQ5Zr2pnp\" data-secret=\"0xQ5Zr2pnp\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n<p class=\"wp-block-paragraph\">That vulnerability was from April; it was a <em>padding oracle<\/em>-type issue in the <strong>EncryptInterceptor<\/strong> component that allowed an attacker to decrypt sensitive information through adaptive attacks against the inter-node encryption mechanism. However, the fixes introduced in versions <strong>9.0.116, 10.1.53, and 11.0.20<\/strong> were incomplete and resulted in a new critical vulnerability, <strong>CVE-2026-34486<\/strong>, which enables <strong>complete bypass of encryption<\/strong> in that same component. To this situation is added <strong>CVE-2026-34487<\/strong>, which affects the <em>cloud membership for clustering<\/em> mechanism in Kubernetes and exposes in the logs the <em>bearer token<\/em> of the <em>service account<\/em> used by Tomcat to interact with the cluster API.<\/p>\n\n<p class=\"wp-block-paragraph\">Taken together, these vulnerabilities show a direct relationship: two of them impact the same cryptographic component and evidence a flawed or insufficient fix, while the third extends the risk toward cloud-native environments by compromising Kubernetes secrets, raising the impact from the inter-node transport layer to the security of the cluster and its associated credentials.<\/p>\n\n<h2 class=\"wp-block-heading\">Mitigation<\/h2>\n\n<p class=\"wp-block-paragraph\">There is no documented temporary mitigation equivalent to applying the patch. As complementary measures while the update is being coordinated:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Disable or isolate Apache Tomcat inter\u2011node clustering if it is not strictly necessary in the affected environment, thus reducing the attack surface exposed to the EncryptInterceptor.<\/li>\n\n\n\n<li>Restrict network access to Tomcat clustering ports only to authorized cluster nodes through firewall or network rules.<\/li>\n\n\n\n<li>Monitor inter\u2011node traffic for anomalous communication patterns between cluster nodes.<\/li>\n\n\n\n<li>Review Tomcat logs looking for unusual incoming connections or clustering activity from IPs not belonging to the legitimate cluster.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<p class=\"wp-block-paragraph\">Update Apache Tomcat to the fixed versions published in April 2026. The update can be performed by downloading the official binary from the Apache Tomcat website and following the manufacturer&#8217;s update procedure.<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Installed product and version<\/strong><\/td><td><strong>Fixed version<\/strong><\/td><td><strong>Update information<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Apache Tomcat 11.x \u2013 versions prior to 11.0.21<\/td><td>11.0.21<\/td><td>https:\/\/tomcat.apache.org\/download-11.cgi<\/td><\/tr><tr><td>Apache Tomcat 10.x \u2013 versions prior to 10.1.54<\/td><td>10.1.54<\/td><td>https:\/\/tomcat.apache.org\/download-10.cgi<\/td><\/tr><tr><td>Apache Tomcat 9.x \u2013 versions prior to 9.0.117<\/td><td>9.0.117<\/td><td>https:\/\/tomcat.apache.org\/download-90.cgi<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>The Hacker News \u2013 CISA Flags Langflow RCE, Tomcat, and N\u2011central Flaws as Actively Exploited<br \/>https:\/\/thehackernews.com\/2026\/08\/cisa-flags-langflow-rce-tomcat-and-n.html<\/li>\n\n\n\n<li>CISA \u2013 Known Exploited Vulnerabilities Catalog<br \/>https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog<\/li>\n\n\n\n<li>NVD \u2013 CVE\u20112026\u201134486<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-34486<\/li>\n\n\n\n<li>Apache Tomcat Security Reports<br \/>https:\/\/tomcat.apache.org\/security.html<\/li>\n\n\n\n<li>Apache Tomcat 11 Downloads<br \/>https:\/\/tomcat.apache.org\/download-11.cgi<\/li>\n\n\n\n<li>Apache Tomcat 10 Downloads<br \/>https:\/\/tomcat.apache.org\/download-10.cgi<\/li>\n\n\n\n<li>Apache Tomcat 9 Downloads<br \/><a href=\"https:\/\/tomcat.apache.org\/download-90.cgi\">https:\/\/tomcat.apache.org\/download-90.cgi<\/a><\/li>\n\n\n\n<li>https:\/\/beaconlab.us\/es\/publicacion\/alerta-2026-35-vulnerabilidades-en-apache-tomcat-y-una-de-ellas-afecta-k8s\/<\/li>\n<\/ul>\n","protected":false},"featured_media":10457,"template":"","class_list":["post-12028","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"5000\" \/>\n\t\t<meta property=\"og:image:height\" content=\"2715\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-05T17:49:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T21:59:28+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#listItem\",\"name\":\"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/\",\"name\":\"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab\",\"description\":\"Affected product(s): Apache Tomcat 11.x \\u2013 versions prior to 11.0.21 Apache Tomcat 10.x \\u2013 versions prior to 10.1.54 Apache Tomcat 9.x \\u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\\u20112026\\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/Apache_Tomcat_Logo.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#mainImage\",\"width\":5000,\"height\":2715},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\\\/#mainImage\"},\"datePublished\":\"2026-08-05T11:49:14-06:00\",\"dateModified\":\"2026-09-29T15:59:28-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab","description":"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#listItem","name":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#listItem","position":2,"name":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/","name":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab","description":"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#mainImage","width":5000,"height":2715},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/#mainImage"},"datePublished":"2026-08-05T11:49:14-06:00","dateModified":"2026-09-29T15:59:28-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab","og:description":"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png","og:image:width":5000,"og:image:height":2715,"article:published_time":"2026-08-05T17:49:14+00:00","article:modified_time":"2026-09-29T21:59:28+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware - Beacon Lab","twitter:description":"Affected product(s): Apache Tomcat 11.x \u2013 versions prior to 11.0.21 Apache Tomcat 10.x \u2013 versions prior to 10.1.54 Apache Tomcat 9.x \u2013 versions prior to 9.0.117 Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE\u20112026\u201134486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being leveraged","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/03\/Apache_Tomcat_Logo.png"},"aioseo_meta_data":{"post_id":"12028","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 21:59:13","updated":"2026-09-29 21:59:48","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-82 Vulnerability in Apache Tomcat actively exploited to distribute SNOWLIGHT malware","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-82-vulnerability-in-apache-tomcat-actively-exploited-to-distribute-snowlight-malware\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12028","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12028\/revisions"}],"predecessor-version":[{"id":12029,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12028\/revisions\/12029"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/10457"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=12028"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}