Critical CVE-2026-34486, CVE-2026-48282 — A Tomcat cluster-encryption bypass caused by an earlier fix, and a CVSS 10 ColdFusion path traversal leading to code execution, are both being exploited. Fixed in Tomcat 11.0.21 / 10.1.54 / 9.0.117 and ColdFusion 2025 Update 10 / 2023 Update 21.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Tomcat 11.0.20, 10.1.53 and 9.0.116 shipped a fix that accidentally let cluster session-replication traffic bypass the EncryptInterceptor. Upgrade to 11.0.21 / 10.1.54 / 9.0.117. ColdFusion 2025 (Update 9 and earlier) and 2023 (Update 20 and earlier) have a CVSS 10 path traversal giving code execution without user interaction. Install ColdFusion 2025 Update 10 / 2023 Update 21.
| CVE-2026-34486 | Tomcat: the fix for CVE-2026-29146 allowed bypass of EncryptInterceptor (cluster replication). Affects exactly 11.0.20, 10.1.53, 9.0.116. KEV 2026-08-04 |
|---|---|
| Tomcat fixed | 11.0.21 · 10.1.54 · 9.0.117 |
| CVE-2026-48282 | ColdFusion path traversal → arbitrary code execution, scope changed. CVSS 10. KEV 2026-07-07 |
| ColdFusion fixed | ColdFusion 2025 Update 10 · ColdFusion 2023 Update 21 (APSB26-68) |
Tomcat’s cluster feature replicates user sessions between nodes, and the EncryptInterceptor encrypts that traffic so someone on the network can’t read or inject session data. A fix for an earlier bug (CVE-2026-29146) introduced a way to bypass the interceptor, in exactly three releases: 11.0.20, 10.1.53 and 9.0.116. If you upgraded to one of those to fix the earlier CVE, you need to upgrade again.
Only clustered Tomcat deployments using EncryptInterceptor are affected. Single-instance Tomcat (most self-hosted apps) doesn’t use cluster replication.
$CATALINA_HOME/bin/version.sh # or catalina.sh version
grep -n EncryptInterceptor $CATALINA_HOME/conf/server.xml
Upgrade to 11.0.21, 10.1.54 or 9.0.117 (or later). Docker images: pull the current tomcat: tag for your line and recreate. Linux distro packages: install your distro’s security update.
A path traversal in ColdFusion lets an attacker reach files outside the intended directory and turn that into arbitrary code execution in the context of the ColdFusion service, with no user interaction and a changed scope (CVSS 10). ColdFusion has a long history of exploited bugs and is still common on older government, education and business sites.
/CFIDE/administrator to the internet; restrict it by IP at the web server..cfm/.cfc files in the web root and CFIDE, and for scheduled tasks you didn’t create (Server Settings → Scheduled Tasks), a favourite persistence trick.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.