Exploitation of Apache Tomcat CVE-2025-24813 Confirmed

Exploitation of Apache Tomcat CVE-2025-24813 Confirmed

First seen 10 Sep 2026, 02:15 UTC Sploitus 72.6

Article Content

Browse articles
ThreatCluster

The CVE-2025-24813 vulnerability in Apache Tomcat, which allows for remote code execution due to a path equivalence issue in the 'file.Name' parameter, is actively being exploited. This vulnerability affects Apache Tomcat servers and was first disclosed on March 10, 2025. Attackers can leverage this flaw through PUT requests that permit writing to paths containing 'file.name'. The TomcatScanner tool has been released to help identify and exploit this vulnerability. Security professionals are urged to assess their systems for exposure to this CVE. The vulnerability was added to CISA's KEV list on April 1, 2025, indicating active exploitation in the wild. Current reports suggest that organizations should prioritize patching and monitoring for signs of exploitation.

Key Points: • CVE-2025-24813 allows remote code execution in Apache Tomcat servers. • Active exploitation has been confirmed, with tools available for attackers. • CISA added this vulnerability to its KEV list, highlighting its severity.

Ask AI about this cluster

Timeline

2025-03-10
CVE-2025-24813 published
Apache Tomcat vulnerability disclosed, allowing remote code execution via 'file.Name' parameter.
Sploitus
2025-04-01
CVE-2025-24813 added to CISA KEV
CISA included CVE-2025-24813 in its Known Exploited Vulnerabilities catalog due to confirmed exploitation.
Sploitus
Recent
TomcatScanner tool released
A new tool, TomcatScanner, was released to help identify and exploit the CVE-2025-24813 vulnerability.
Sploitus