<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aapachetomcat10.1.0milestone4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 18:54:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aapachetomcat10.1.0milestone4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2025-24813-tomcat-rce/</link><pubDate>Tue, 08 Sep 2026 18:54:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2025-24813-tomcat-rce/</guid><description>A critical remote code execution vulnerability (CVE-2025-24813) in Apache Tomcat with a CVSS score of 10.0 is now being targeted by publicly available proof-of-concept exploit tools.</description><content:encoded><![CDATA[<p>Apache Tomcat is vulnerable to a critical remote code execution (RCE) flaw tracked as CVE-2025-24813. The vulnerability is rated at CVSS 10.0 and allows unauthenticated attackers to execute arbitrary code over the network without requiring user interaction. Impacted versions include Apache Tomcat releases prior to 9.0.99, 10.1.35, and 11.0.3, as well as specific earlier iterations in the 10.1.x and 11.0.x branches. Following the public disclosure, exploit scripts and multi-threaded scanning tools have been released on platforms like GitHub, significantly lowering the barrier for entry for malicious actors to identify and compromise exposed instances. Given the severity of the RCE and the presence of functional PoC code, organizations running affected Tomcat servers are at high risk of immediate compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2025-24813 grants attackers full control over the vulnerable Apache Tomcat instance. As the vulnerability allows unauthenticated RCE, attackers can achieve complete system compromise, data exfiltration, and lateral movement within the network. The CVSS 10.0 score indicates that the impact on confidentiality, integrity, and availability is total, potentially affecting any enterprise environment using these versions of Tomcat for application hosting.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch Apache Tomcat to the latest versions (9.0.99, 10.1.35, or 11.0.3) immediately.</li>
<li>Inventory internet-facing Apache Tomcat instances and move them behind WAF/authentication layers if patching cannot be performed immediately.</li>
<li>Monitor web server logs for suspicious requests involving unexpected command injection attempts or unusual POST methods aimed at Tomcat endpoints.</li>
<li>Deploy detection logic to monitor for unexpected child processes spawned by the Tomcat Java process (e.g., cmd.exe, sh, or powershell.exe).</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>webserver</category></item></channel></rss>