Skip to content
Exploits Targeting Tomcat Vulnerabilities CVE-2017-12615 and CVE-2020-1938

Exploits Targeting Tomcat Vulnerabilities CVE-2017-12615 and CVE-2020-1938

First seen 24 Sep 2026, 01:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 02:27 UTC

Recent cybersecurity tools have emerged that exploit vulnerabilities in Apache Tomcat, specifically CVE-2017-12615 and CVE-2020-1938. The TomcatScanPro tool, released on September 19, 2026, allows users to check for weak passwords and exploit CVE-2017-12615, which has been actively exploited since its disclosure in 2017. Additionally, the AttackTomcat tool, published on September 23, 2026, focuses on file upload vulnerabilities and weak authentication, targeting CVE-2020-1938. Both tools enable attackers to gain unauthorized access to sensitive information on Tomcat servers. The tools support multiple URL checks and utilize efficient resource management techniques. Organizations using Apache Tomcat are advised to assess their configurations and apply necessary security measures against these exploits.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2017-09-19
CVE-2017-12615 published
A vulnerability in Apache Tomcat allowing unauthorized access through weak passwords was disclosed.
Sploitus
2020-02-24
CVE-2020-1938 published
A vulnerability in Apache Tomcat that allows file inclusion and reading was disclosed.
Sploitus
2022-03-03
CVE-2020-1938 added to CISA KEV
CISA confirmed active exploitation of CVE-2020-1938 in the wild.
Sploitus
2022-03-25
CVE-2017-12615 added to CISA KEV
CISA confirmed active exploitation of CVE-2017-12615 in the wild.
Sploitus
2026-09-19
TomcatScanPro released
A new tool for exploiting CVE-2017-12615 and checking weak passwords was published.
Sploitus
2026-09-23
AttackTomcat released
Another tool targeting CVE-2020-1938 and weak authentication was published.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2017-12615 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed