AI-Driven Attacks Target Apache Tomcat: Update Now
What happened
On 4 August 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-34486 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Apache Tomcat – a web server used to run a huge number of business applications – and attackers are already using it to break into servers and install malicious software.
What sets this incident apart is how the attackers are operating. Researchers at Palo Alto Networks Unit 42 attributed the campaign to a Chinese-speaking threat actor who used DeepSeek – a large language model – via an autonomous offensive framework called Hermes Agent to automatically scan for and exploit vulnerable servers without a human making each decision step by step. An AI carried out the hacking campaign.
What Apache Tomcat is, and whether it is in your business
Apache Tomcat is an open-source web application server. If your business runs web-based software – an ERP system, CRM platform, HR or payroll portal, document management tool, or custom-built business application – there is a reasonable chance it runs on Tomcat under the hood, even if the product name gives no indication of that.
Tomcat is particularly common where multiple servers share workload in a cluster (a setup used to improve speed and resilience). It is widely used across manufacturing, professional services, finance, healthcare, and the public sector. It is also common in businesses that have commissioned bespoke web applications. If you run any Java-based software on your own servers or on hosted infrastructure you manage, it is worth checking.
What the flaw does
CVE-2026-34486 is a weakness in the way Tomcat encrypts traffic between servers in a clustered setup. A security component called EncryptInterceptor – designed to protect that inter-server communication – can be bypassed. An attacker who exploits this on a vulnerable clustered deployment can intercept sensitive data passing between servers, or use a technique called Java deserialization to run their own code on the machine.
From there, attackers can move laterally across your network, steal data, or deploy ransomware. The active campaign observed by Unit 42 was deploying reverse shells – tools that give attackers persistent remote command access to compromised servers.
The vulnerable versions are Apache Tomcat 11.0.20, 10.1.53, and 9.0.116. Patches are available now: upgrade to 11.0.21, 10.1.54, or 9.0.117 respectively.
Why the AI-driven campaign is significant
We have written before about how AI is being used to craft more convincing phishing emails and deepfake scams. This case goes a step further: the AI is not writing emails – it is acting as an autonomous operator, identifying targets and launching exploits automatically across thousands of internet-connected servers.
This changes the economics of cyber attacks. Smaller businesses that a skilled attacker might previously have overlooked are now fair game, because the cost of running an AI-driven scan across the internet is negligible. If your servers are running a vulnerable version and are reachable from the internet, they will be found.
It is also a reminder of why patching speed matters. Unpatched systems that sit exposed for days or weeks after a vulnerability is published are not just theoretically at risk – they are being actively probed by automated tools that never stop running.
What to do now
If your business manages its own servers or web applications:
- Check whether Apache Tomcat is running anywhere in your environment. Your IT team or a server audit will confirm this. It may be installed as a dependency of business software rather than as a product you chose directly.
- If you are on version 11.0.20, 10.1.53, or 9.0.116, upgrade to 11.0.21, 10.1.54, or 9.0.117 immediately.
- If your Tomcat instances are part of a clustered setup, treat this as the highest priority. The EncryptInterceptor bypass is the active attack path.
- Review firewall rules to ensure Tomcat’s cluster communication ports (typically 4000 and 45564) are not exposed to the public internet.
If a managed IT provider looks after your infrastructure, ask them specifically about Apache Tomcat patching and cluster port exposure.
How System Force IT can help
Monitoring vulnerability catalogues like the CISA KEV and acting quickly when flaws enter active exploitation is a core part of our managed IT service. We keep our clients’ server estates patched and review their exposure when advisories like this one appear.
If you are unsure whether Apache Tomcat is running in your environment, our IT security team can carry out a review and advise on your patching position. We can also help you put the right firewall rules and monitoring in place so that actively-exploited flaws like this one do not catch your business off guard.
Get in touch via our contact page or call 01452 701355 for a no-obligation conversation about your server security.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


