NINJA SIGNAL
DEFCON··MAXIMUM

TODAY

Apache Tomcat encryption bypass now actively exploited — patch all eight threats today.

THE THREE

  1. #1 · CVE-2026-34486

    Apache

    KEV

    What: If your organization runs Apache Tomcat (versions 9, 10, or 11), attackers can bypass the encryption that protects sensitive data in transit — meaning credentials, session tokens, or application data can be intercepted or tampered with. With an 83% exploit probability and active exploitation confirmed, this is being hit right now.

    Why it moved: Actively exploited · Everyone runs this · 83% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Upgrade Apache Tomcat to 11.0.21, 10.1.54, or 9.0.117 immediately.

  2. #2 · CVE-2026-10520

    Ivanti

    KEV

    What: Ivanti Sentry (MobileIron Sentry) has a perfect 10.0 CVSS score and near-certain exploit odds — an unauthenticated attacker on the internet can gain full root control of your mobile device management gateway, exposing every managed device and corporate email account behind it.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Isolate Ivanti Sentry from the internet and apply Ivanti's patch now.

  3. #3 · CVE-2026-0257

    Palo Alto

    KEV

    What: Attackers can bypass authentication on Palo Alto PAN-OS firewalls and create unauthorized VPN connections, effectively walking past your perimeter as if they were a trusted employee — full network access without valid credentials.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 94% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply the Palo Alto PAN-OS patch and audit active VPN sessions for anomalies.

TRAVERSAL

Graph links this vulnerability to maven/org.apache.tomcat:tomcat-tribes.

software · maven/org.apache.tomcat:tomcat-tribessoftware · maven/org.apache.tomcat:tomcatsoftware · maven/org.apache.tomcat.embed:tomcat-embed-core

NUMBERS

Entities
10M
Relationships
62M
Threat actors
352
Indicators
547k
Feeds live
0
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.