⤷ Title: Remote code execution in Apache Tomcat (RCE)
════════════════════════
𐀪 Author: Kaique
════════════════════════
ⴵ Time: Fri, 28 Mar 2025 19:31:35 GMT
════════════════════════
⌗ Tags: #writeup #reverse_shell #rce_vulnerability #security_misconfiguration #apache_tomcat
════════════════════════
𐀪 Author: Kaique
════════════════════════
ⴵ Time: Fri, 28 Mar 2025 19:31:35 GMT
════════════════════════
⌗ Tags: #writeup #reverse_shell #rce_vulnerability #security_misconfiguration #apache_tomcat
Medium
😺 Remote code execution in Apache Tomcat (RCE)
Explorando falhas de configuração para obter acesso remoto ao servidor
⤷ Title: CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Wed, 02 Apr 2025 02:00:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CVE_2025_24813
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Wed, 02 Apr 2025 02:00:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CVE_2025_24813
Daily CyberSecurity
CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS
CVE-2025-24813 vulnerability in Apache Tomcat, now actively exploited in the wild, has landed in the CISA Known Exploited Vulnerabilities Catalog
⤷ Title: Apache Tomcat Security Update Fixes DoS and Rewrite Rule Bypass Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Apr 2025 01:38:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CVE_2025_31650 #CVE_2025_31651 #Denial of Service #Java Servlet #Rewrite Rule Bypass #security update #vulnerability patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Apr 2025 01:38:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CVE_2025_31650 #CVE_2025_31651 #Denial of Service #Java Servlet #Rewrite Rule Bypass #security update #vulnerability patch
Daily CyberSecurity
Apache Tomcat Security Update Fixes DoS and Rewrite Rule Bypass Flaws
Apache Tomcat patches CVE-2025-31650 and CVE-2025-31651 to fix denial of service and rewrite rule bypass issues. Upgrade now to stay secure.
⤷ Title: Apache Tomcat Flaw Allows Security Bypass on Case-Insensitive Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 May 2025 01:52:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CGI servlet #macOS #security bypass #web server #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 May 2025 01:52:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CGI servlet #macOS #security bypass #web server #windows
Daily CyberSecurity
Apache Tomcat Flaw Allows Security Bypass on Case-Insensitive Systems
A low-severity flaw in Apache Tomcat (CVE-2025-46701) allows security constraint bypass via crafted URLs on case-insensitive file systems. Update now!
⤷ Title: Critical Flaws in Veritas DLO Expose Systems to Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:26:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache HTTP Server #apache Tomcat #CISA KEV #cybersecurity #data backup #endpoint protection #rce #Remote Code Execution #Veritas DLO
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:26:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache HTTP Server #apache Tomcat #CISA KEV #cybersecurity #data backup #endpoint protection #rce #Remote Code Execution #Veritas DLO
Daily CyberSecurity
Critical Flaws in Veritas DLO Expose Systems to Remote Code Execution
Veritas DLO has critical vulnerabilities (CVE-2024-38475, CVE-2025-24813) in bundled Apache components, leading to RCE. Upgrade immediately to prevent exploitation.
⤷ Title: Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:08:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #Brute Force #cyberattack #cybersecurity #DigitalOcean #GreyNoise #Login Attempts #Tomcat Manager #Web Security #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:08:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #Brute Force #cyberattack #cybersecurity #DigitalOcean #GreyNoise #Login Attempts #Tomcat Manager #Web Security #web server
Daily CyberSecurity
Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces
GreyNoise reports a massive brute-force campaign targeting Apache Tomcat Manager interfaces, with hundreds of malicious IPs attempting to compromise services.
⤷ Title: Apache Tomcat Patches 4 Flaws: DoS, Privilege Bypass, & Installer Risks Addressed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:19:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2025_48976 #CVE_2025_48988 #CVE_2025_49124 #CVE_2025_49125 #Denial of Service #dos #Installer #java #Privilege Bypass #Vulnerability #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:19:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2025_48976 #CVE_2025_48988 #CVE_2025_49124 #CVE_2025_49125 #Denial of Service #dos #Installer #java #Privilege Bypass #Vulnerability #web server
Daily CyberSecurity
Apache Tomcat Patches 4 Flaws: DoS, Privilege Bypass, & Installer Risks Addressed
Apache Tomcat patched four vulnerabilities affecting versions 9.0, 10.1, and 11.0, ranging from DoS to privilege bypass. Update immediately
⤷ Title: Apache Under Attack: Critical RCE Flaws in Tomcat & Camel Spark Thousands of Exploit Attempts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:39:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Camel #apache Tomcat #CVE_2025_24813 #CVE_2025_27636 #CVE_2025_29891 #cybersecurity #Palo Alto Networks #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 00:39:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Camel #apache Tomcat #CVE_2025_24813 #CVE_2025_27636 #CVE_2025_29891 #cybersecurity #Palo Alto Networks #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Apache Under Attack: Critical RCE Flaws in Tomcat & Camel Spark Thousands of Exploit Attempts
Palo Alto Networks reveals thousands of exploit attempts targeting RCE flaws in Apache Tomcat (CVE-2025-24813) and Apache Camel (CVE-2025-27636, CVE-2025-29891).
⤷ Title: Apache Tomcat Patches Trio of Denial-of-Service Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:29:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #APR #Denial of Service #dos #file upload #HTTP/2 #Multipart #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:29:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #APR #Denial of Service #dos #file upload #HTTP/2 #Multipart #web server
Daily CyberSecurity
Apache Tomcat Patches Trio of Denial-of-Service Flaws
Apache Tomcat 9.0.107 patches three critical DoS flaws (CVE-2025-52434, CVE-2025-52520, CVE-2025-53506) that can disrupt web services via HTTP/2, file uploads, and excessive streams.
⤷ Title: Apache Tomcat webshell application for RCE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 15:47:42 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Apache Tomcat webshell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 15:47:42 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Apache Tomcat webshell
Penetration Testing Tools
Apache Tomcat webshell application for RCE
Apache Tomcat webshell application for RCE is a webshell application and interactive shell for pentesting Apache Tomcat servers.
⤷ Title: Patch Now: Apache Tomcat Fixes Session Fixation and ‘MadeYouReset’ Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 00:17:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CVE_2025_48989 #CVE_2025_55668 #dos #MadeYouReset #security update #Session Fixation #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 00:17:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #CVE_2025_48989 #CVE_2025_55668 #dos #MadeYouReset #security update #Session Fixation #web server
Daily CyberSecurity
Patch Now: Apache Tomcat Fixes Session Fixation and 'MadeYouReset' Flaws
Apache Tomcat has released updates for two serious flaws: a session fixation vulnerability and a "MadeYouReset" DoS vulnerability affecting multiple versions.
⤷ Title: Apache Tomcat Patches URL Rewrite Bypass (CVE-2025-55752) Risking RCE and Console ANSI Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:43:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ANSI Escape #apache Tomcat #CVE_2025_55752 #Denial of Service #rce #URL Rewrite Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:43:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ANSI Escape #apache Tomcat #CVE_2025_55752 #Denial of Service #rce #URL Rewrite Bypass
Daily CyberSecurity
Apache Tomcat Patches URL Rewrite Bypass (CVE-2025-55752) Risking RCE and Console ANSI Injection
The Apache Software Foundation has released multiple security patches for Apache Tomcat, addressing three newly disclosed vulnerabilities — CVE-2025-55752, CVE-2025-55754, and CVE-2025-61795 — aff…
⤷ Title: Bypassing the Bouncer: Apache Tomcat Patches SNI & Legacy Protocol Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 05:58:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2025_66614 #CVE_2026_24733 #CVE_2026_24734 #Cyber Security #HTTP/0.9 #infosec #Patch Alert #SNI Bypass #Web Server Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 05:58:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2025_66614 #CVE_2026_24733 #CVE_2026_24734 #Cyber Security #HTTP/0.9 #infosec #Patch Alert #SNI Bypass #Web Server Security
Daily CyberSecurity
Bypassing the Bouncer: Apache Tomcat Patches SNI & Legacy Protocol Flaws
Apache Tomcat rolls out urgent updates for versions 9, 10, and 11 to fix legacy HTTP/0.9 protocol confusion and SNI certificate bypass flaws. Patch now.
⤷ Title: From Vulnerability to Resilience: Hardening an Apache Tomcat Server (Hands-on Security Walkthrough)
════════════════════════
𐀪 Author: Umeshpandeybtech
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 14:34:00 GMT
════════════════════════
⌗ Tags: #application_security #apache_tomcat_security #penetration_testing #web_server_hardening #cybersecurity
════════════════════════
𐀪 Author: Umeshpandeybtech
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 14:34:00 GMT
════════════════════════
⌗ Tags: #application_security #apache_tomcat_security #penetration_testing #web_server_hardening #cybersecurity
Medium
From Vulnerability to Resilience: Hardening an Apache Tomcat Server (Hands-on Security Walkthrough)
🧠 Why This Matters
⤷ Title: [Thompson] — Exploitation of Apache Tomcat Default Credentials Leading to RCE and Cron-Based…
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 09:46:44 GMT
════════════════════════
⌗ Tags: #rce #crontab #privilege_escalation #apache_tomcat #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 09:46:44 GMT
════════════════════════
⌗ Tags: #rce #crontab #privilege_escalation #apache_tomcat #bug_bounty
Medium
[Thompson] — Exploitation of Apache Tomcat Default Credentials Leading to RCE and Cron-Based Privilege Escalation
From exposed Tomcat manager access to root shell via crontab.
⤷ Title: Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:00:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2026_29146 #CVE_2026_34486 #Encryption Bypass #infosec #Java security #Kubernetes Security #request smuggling #vulnerability management #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 01:00:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2026_29146 #CVE_2026_34486 #Encryption Bypass #infosec #Java security #Kubernetes Security #request smuggling #vulnerability management #web server
Daily CyberSecurity
Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
Apache Tomcat discloses 10 vulnerabilities including encryption bypasses and Kubernetes token leaks. Upgrade now to secure your Java-based web applications.
⤷ Title: Apache Tomcat RCE Details and Exploit Code Now Public
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 03:22:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #Cyber Security #EncryptInterceptor #Exploit PoC #infosec #Java security #Patch Alert #rce #vulnerability disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 03:22:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #Cyber Security #EncryptInterceptor #Exploit PoC #infosec #Java security #Patch Alert #rce #vulnerability disclosure
Daily CyberSecurity
Apache Tomcat RCE Details and Exploit Code Now Public
Apache Tomcat RCE alert: CVE-2026-34486 exploit code and details are now public. A "fail-open" flaw enables RCE via Tribes clustering. Update immediately.
⤷ Title: Ghostcat-PWN: When an Old Tomcat Vulnerability Opens the org doors
════════════════════════
𐀪 Author: Deepanshu khanna
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 13:59:23 GMT
════════════════════════
⌗ Tags: #cve_2020_1938 #apache_tomcat #red_team #penetration_testing #security_testing
════════════════════════
𐀪 Author: Deepanshu khanna
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 13:59:23 GMT
════════════════════════
⌗ Tags: #cve_2020_1938 #apache_tomcat #red_team #penetration_testing #security_testing
Medium
Ghostcat-PWN: When an Old Tomcat Vulnerability Opens the org doors
From exposed AJP connectors to reliable post-exploitation workflows: the story behind Ghostcat-PWN and our experience with CVE-2020–1938
⤷ Title: Apache Tomcat Vulnerabilities Allow Authentication Bypass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 02:31:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #Authentication Bypass #CVE_2026_55957 #GSSAPI #JNDIRealm #Tomcat security #Tomcat vulnerability #Web Server Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 02:31:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #Authentication Bypass #CVE_2026_55957 #GSSAPI #JNDIRealm #Tomcat security #Tomcat vulnerability #Web Server Security
Daily CyberSecurity
Apache Tomcat Vulnerabilities Allow Authentication Bypass
TL;DR The Apache Tomcat project disclosed seven vulnerabilities on 29 June 2026. The most serious Apache Tomcat vulnerabilities let an attacker bypass authentication. The flaws span Tomcat 7 throu…
⤷ Title: Exploiting Apache Tomcat Ghostcat (CVE-2020–1938): From Initial Access to Root | TryHackMe…
════════════════════════
𐀪 Author: Gokulnaath | Offensive Security
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:14:13 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cve_2020_1938 #penetration_testing #apache_tomcat #cybersecurity
════════════════════════
𐀪 Author: Gokulnaath | Offensive Security
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:14:13 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cve_2020_1938 #penetration_testing #apache_tomcat #cybersecurity
Medium
Exploiting Apache Tomcat Ghostcat (CVE-2020–1938): From Initial Access to Root | TryHackMe…
Introduction