{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapachetomcat10.1.0milestone1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone15:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone16:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone17:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone18:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone19:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone20:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-24813"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Tomcat (\u003c 9.0.99, 10.1.35, 11.0.3, 10.1.0, 11.0.0)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","webserver"],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache Tomcat is vulnerable to a critical remote code execution (RCE) flaw tracked as CVE-2025-24813. The vulnerability is rated at CVSS 10.0 and allows unauthenticated attackers to execute arbitrary code over the network without requiring user interaction. Impacted versions include Apache Tomcat releases prior to 9.0.99, 10.1.35, and 11.0.3, as well as specific earlier iterations in the 10.1.x and 11.0.x branches. Following the public disclosure, exploit scripts and multi-threaded scanning tools have been released on platforms like GitHub, significantly lowering the barrier for entry for malicious actors to identify and compromise exposed instances. Given the severity of the RCE and the presence of functional PoC code, organizations running affected Tomcat servers are at high risk of immediate compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-24813 grants attackers full control over the vulnerable Apache Tomcat instance. As the vulnerability allows unauthenticated RCE, attackers can achieve complete system compromise, data exfiltration, and lateral movement within the network. The CVSS 10.0 score indicates that the impact on confidentiality, integrity, and availability is total, potentially affecting any enterprise environment using these versions of Tomcat for application hosting.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch Apache Tomcat to the latest versions (9.0.99, 10.1.35, or 11.0.3) immediately.\u003c/li\u003e\n\u003cli\u003eInventory internet-facing Apache Tomcat instances and move them behind WAF/authentication layers if patching cannot be performed immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests involving unexpected command injection attempts or unusual POST methods aimed at Tomcat endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy detection logic to monitor for unexpected child processes spawned by the Tomcat Java process (e.g., cmd.exe, sh, or powershell.exe).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T18:54:27Z","date_published":"2026-09-08T18:54:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-24813-tomcat-rce/","summary":"A critical remote code execution vulnerability (CVE-2025-24813) in Apache Tomcat with a CVSS score of 10.0 is now being targeted by publicly available proof-of-concept exploit tools.","title":"Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-24813-tomcat-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}