Security News

Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters: Are You at Risk?
2025-03-19 16:30

By simply sending HTTP requests, attackers can trigger the deserialisation of malicious data in Tomcat's session storage and gain control.

'Dead simple' hijacking hole in Apache Tomcat 'now actively exploited in the wild'
2025-03-18 00:44

One PUT request, one poisoned session file, and the server’s yours A trivial flaw in Apache Tomcat that allows remote code execution and access to sensitive files is said to be under attack in the...

Apache Tomcat Vulnerability Actively Exploited Just 30 Hours After Public Disclosure
2025-03-17 17:08

A recently disclosed security flaw impacting Apache Tomcat has come under active exploitation in the wild following the release of a public proof-of-concept (PoC) a mere 30 hours after public...

Critical RCE flaw in Apache Tomcat actively exploited in attacks
2025-03-17 13:29

A critical remote code execution (RCE) vulnerability in Apache Tomcat tracked as CVE-2025-24813 is actively exploited in the wild, enabling attackers to take over servers with a simple PUT request. [...]

Apache Tomcat Vulnerability CVE-2024-56337 Exposes Servers to RCE Attacks
2024-12-24 06:06

The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in remote code execution (RCE) under...

Apache fixes remote code execution bypass in Tomcat web server
2024-12-23 12:33

Apache has released a security update that addresses an important vulnerability in Tomcat web server that could lead to an attacker achieving remote code execution. [...]

Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining
2023-07-27 10:46

Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners. The findings come...

Apache Tomcat Exploit Poised to Pounce, Stealing Files
2020-03-23 20:56

A vulnerability in the popular Apache Tomcat web server is ripe for active attack, thanks to a proof-of-concept exploit making an appearance on GitHub. The Apache Tomcat open-source web server supports various JavaScript-based technologies, including the Apache JServ Protocol interface, which is where the vulnerability resides.

Apache Tomcat Exploit Poised to Pounce, Stealing Files
2020-03-23 20:56

A vulnerability in the popular Apache Tomcat web server is ripe for active attack, thanks to a proof-of-concept exploit making an appearance on GitHub. The Apache Tomcat open-source web server supports various JavaScript-based technologies, including the Apache JServ Protocol interface, which is where the vulnerability resides.

Hackers Scanning for Apache Tomcat Servers Vulnerable to Ghostcat Attacks
2020-03-05 12:29

Hackers have started scanning the web in search of Apache Tomcat servers affected by a recently disclosed vulnerability tracked as CVE-2020-1938 and dubbed Ghostcat. Bad Packets told SecurityWeek on Wednesday that the scanning activity they have detected is designed to enumerate vulnerable servers by checking for the path "/WEB-INF/web.