Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Apache Tomcat CVE-2026-34486 and Adobe ColdFusion CVE-2026-48282: Exploited Java App Server Bugs

Critical CVE-2026-34486, CVE-2026-48282 — A Tomcat cluster-encryption bypass caused by an earlier fix, and a CVSS 10 ColdFusion path traversal leading to code execution, are both being exploited. Fixed in Tomcat 11.0.21 / 10.1.54 / 9.0.117 and ColdFusion 2025 Update 10 / 2023 Update 21.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Tomcat 11.0.20, 10.1.53 and 9.0.116 shipped a fix that accidentally let cluster session-replication traffic bypass the EncryptInterceptor. Upgrade to 11.0.21 / 10.1.54 / 9.0.117. ColdFusion 2025 (Update 9 and earlier) and 2023 (Update 20 and earlier) have a CVSS 10 path traversal giving code execution without user interaction. Install ColdFusion 2025 Update 10 / 2023 Update 21.

CVE-2026-34486Tomcat: the fix for CVE-2026-29146 allowed bypass of EncryptInterceptor (cluster replication). Affects exactly 11.0.20, 10.1.53, 9.0.116. KEV 2026-08-04
Tomcat fixed11.0.21 · 10.1.54 · 9.0.117
CVE-2026-48282ColdFusion path traversal → arbitrary code execution, scope changed. CVSS 10. KEV 2026-07-07
ColdFusion fixedColdFusion 2025 Update 10 · ColdFusion 2023 Update 21 (APSB26-68)

Apache Tomcat: CVE-2026-34486

Tomcat’s cluster feature replicates user sessions between nodes, and the EncryptInterceptor encrypts that traffic so someone on the network can’t read or inject session data. A fix for an earlier bug (CVE-2026-29146) introduced a way to bypass the interceptor, in exactly three releases: 11.0.20, 10.1.53 and 9.0.116. If you upgraded to one of those to fix the earlier CVE, you need to upgrade again.

Only clustered Tomcat deployments using EncryptInterceptor are affected. Single-instance Tomcat (most self-hosted apps) doesn’t use cluster replication.

$CATALINA_HOME/bin/version.sh            # or catalina.sh version
grep -n EncryptInterceptor $CATALINA_HOME/conf/server.xml

Upgrade to 11.0.21, 10.1.54 or 9.0.117 (or later). Docker images: pull the current tomcat: tag for your line and recreate. Linux distro packages: install your distro’s security update.

Adobe ColdFusion: CVE-2026-48282

A path traversal in ColdFusion lets an attacker reach files outside the intended directory and turn that into arbitrary code execution in the context of the ColdFusion service, with no user interaction and a changed scope (CVSS 10). ColdFusion has a long history of exploited bugs and is still common on older government, education and business sites.

  • Affected: ColdFusion 2025 Update 9 and earlier, ColdFusion 2023 Update 20 and earlier. ColdFusion 2021 and older are out of support.
  • Check: ColdFusion Administrator → Server Update → Updates, or System Information.
  • Fix: install ColdFusion 2025 Update 10 or 2023 Update 21 from the Administrator and restart the service. Then apply Adobe’s lockdown guide if you haven’t.
  • Never expose /CFIDE/administrator to the internet; restrict it by IP at the web server.

Check for compromise

  • ColdFusion: look for new .cfm/.cfc files in the web root and CFIDE, and for scheduled tasks you didn’t create (Server Settings → Scheduled Tasks), a favourite persistence trick.
  • Tomcat clusters: if replication traffic crossed an untrusted network on an affected version, invalidate sessions after upgrading (restart all nodes) so injected sessions don’t survive.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories