Tomcat is a technology platform tracked across 13 threat clusters and 18 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity July 17, 2026.
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux…
On June 10, 2026, Ubuntu released USN-8417-1, addressing multiple vulnerabilities in Tomcat, including denial of service and authentication bypass issues. The vulnerabilities affect various Ubuntu versions, including…
On March 12, 2026, SUSE issued a critical security update for Tomcat 11.0.18 to address several vulnerabilities, including CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734. The vulnerabilities include a client…
The Spring4Shell vulnerability, affecting certain Spring-based Java applications, was disclosed on July 16, 2026. This exploit allows attackers to write malicious payloads to disk under specific conditions, including…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
On July 15, 2026, openSUSE released a security update for Tomcat addressing several vulnerabilities. The update includes fixes for CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, CVE-2026-55955, and…
OpenAI has implemented two new security features in ChatGPT to prevent prompt injection attacks. Meanwhile, threat actors have exploited two Ivanti zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, to deploy…
On February 27, 2026, a security incident was identified involving a single IP address that initially requested a login page. This IP later appended ?debug=true across multiple hosts, indicating probing behavior by an…