CVE-2025-24813Disclosure(apache / bootstrap_os)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch apache bootstrap_os systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

8.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-22. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-44CWE-502CWE-706

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bootstrap_os
  • debian_linux
  • hci_compute_node
  • tomcat

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-09-27)
  • 13 total mentions across 8 days

Affected systems

Products
bootstrap_osdebian_linuxhci_compute_nodetomcat

4 versions affected across 4 products

Deep dive

Activity timeline13 mentions / 8d
01223Mentions · 2026-02-02: 1Mentions · 2026-03-25: 1Mentions · 2026-05-30: 1Mentions · 2026-08-06: 2Mentions · 2026-08-30: 1Mentions · 2026-09-16: 2Mentions · 2026-09-19: 2Mentions · 2026-09-27: 3PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-05-30: 1PoC Mentioned / Linked · 2026-09-16: 1PoC Mentioned / Linked · 2026-09-19: 1Exploit Tool / Code · 2026-09-16: 1Exploit Tool / Code · 2026-09-19: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-08-06: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-03-25: 1Technical Details · 2026-05-30: 1Technical Details · 2026-08-06: 2Technical Details · 2026-08-30: 102-0203-2505-3008-0608-3009-1609-1909-27
Signal classification5 categories
Disclosure
440.0%
Active Exploitation
220.0%
Exploit
220.0%
General
110.0%
Patch
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-03-251
Active Exploitation1
2026-05-301
Disclosure1
2026-08-062
Active Exploitation1Disclosure1
2026-08-301
Patch1
2026-09-162
Disclosure1Exploit1
2026-09-192
Disclosure1Exploit1
Full discourse13 posts
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    CISA confirms active exploitation of Langflow, N-central and Apache Tomcat vulnerabilities CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, confirming evidence of exploitation in real attacks: ⚠️ CVE-2026-9198: Critical unauthenticated remote-code execution in IBM Langflow OSS. ⚠️ CVE-2026-18577: Authentication bypass affecting N-able N-central. ⚠️ CVE-2025-24813: Apache Tomcat flaw capable of enabling remote code execution or information disclosure under vulnerable configurations. Federal civilian agencies were given an unusually short three-day remediation deadline, reflecting the immediate risk. #DDW #DarkWeb #Vulnerabilities #CISA Source: https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has confirmed that CVE-2026-9198, CVE-2026-18577, and CVE-2025-24813 are actively exploited in real attacks, but no patches or PoCs are detailed in this announcement.

    1101246.9K
    206.7K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Disclosure

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: #Apache #Tomcat #Zafiyet: Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) CVE: CVE-2026-34486 Zafiyet Türü: Missing Encryption of Sensitive Data (CWE-311) Fidye Yazılımı İlişkisi: Şu an için bilinmiyor. 📌 Zafiyet Özeti Apache Tomcat üzerinde Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) zafiyeti tespit edilmiştir. Bu güvenlik açığı, EncryptInterceptor bileşeninin atlatılmasına (bypass) olanak tanıyabilir. Ayrıca zafiyet, CVE-2025-24813 ile zincirleme (chained) olarak kullanıldığında daha kapsamlı saldırı senaryolarına zemin hazırlayabilir. Başarılı bir istismarda saldırgan; hassas verileri riske atabilir, iletişim güvenliğini zayıflatabilir ve diğer zafiyetlerle sistemi ele geçirebilir. 🛡️ Önerilen Aksiyonlar ✅ Güvenlik Güncellemeleri Apache tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın. Apache Tomcat'i desteklenen en güncel sürüme yükseltin. ✅ Risk Yönetimi Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin. ✅ Erişim Kontrolleri İnternete açık Tomcat sunucularını öncelikli olarak değerlendirin. Şifreleme yapılandırmalarını doğrulayın ve EncryptInterceptor kullanımını gözden geçirin. Yönetim arayüzünü yalnızca güvenilir ağlardan erişilebilir hale getirin ve erişim kayıtlarını düzenli olarak izleyin. ✅ Geçici Koruma Önlemleri Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, Tomcat sunucusunun internet erişimini sınırlandırın veya yalnızca VPN üzerinden erişilebilir hale getirin. Gerekirse etkilenen bileşenleri geçici olarak devre dışı bırakmayı değerlendirin. 📚 Referans: Apache Security Advisory & CISA

    Post summary

    The bulletin announces a new Apache Tomcat vulnerability (CVE‑2026‑34486), details its technical aspects, and recommends applying official security updates and mitigations.

    030110107
    521 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2026-21858 CVE-2026-53576 CVE-2026-61732 CVE-2020-24186 CVE-2025-24813 ..🧵👇

    11071515
    371 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2026-21858 · CVE-2026-53576 (Kestra) · PoC live ├ CVE-2026-61732 · PoC live └ CVE-2020-24186 · CVE-2025-24813 (Apache GOExploiter) · PoC live

    1003067
    371 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2021-44228 CVE-2025-24813 CVE-2025-32433 CVE-2026-32604 CVE-2024-30804 ..🧵👇

    Post summary

    The post lists several CVEs as critical exploits disclosed today, but provides no further details on PoC, patches, or active exploitation.

    1101088
    50 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2025-24813 [CRITICAL/PoC] Apache-GOExploiter 🔗 https://exploitgrid.net/exploits/488ef901-d0b9-40b5-a67b-a05f7b7e3988

    1000054
    356 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2025-24813 [CRITICAL/PoC] CVE-2025-24813-POC 🔗 https://exploitgrid.net/exploits/751fdfd3-c7e9-4d01-9402-1746d9967187

    Post summary

    The post announces the availability of a functional exploit for CVE-2025-24813, explicitly tagged as '[EXPLOIT]' and '[CRITICAL/PoC]', with a direct link to the exploit code hosted on ExploitGrid.

    1000043
    50 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2025-24813 [CRITICAL/PoC] CVE-2025-24813 🔗 https://exploitgrid.net/exploits/d32fbd51-e7aa-40fc-b255-432b0d20bde9

    Post summary

    The post announces the availability of an exploit for CVE-2025-24813 and provides a direct link to the exploit on exploitgrid.net.

    1000046
    45 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2024-3094 CVE-2025-24813 CVE-2026-48907 CVE-2026-38526 CVE-2024-36401 ..🧵👇

    Post summary

    The tweet discloses that multiple CVEs were published today as part of a threat digest, without giving exploitation details, patches, or PoC information.

    1000071
    45 followersView on X
  • Soy Nube Negra@Soy_Nube_Negra
    Patch

    🛡️ [APACHE TOMCAT] — CVE-2026-34486: omisión de cifrado en EncryptInterceptor. Impacto: Tomcat con el interceptor de cifrado habilitado permite a un atacante omitir la protección y, encadenado con CVE-2025-24813, alcanzar exposición o movimiento lateral en clusters mal configurados. Está en el catálogo KEV de CISA (agregado el 4 de agosto). Estado: incluido en CISA KEV; parche disponible en las notas de la lista de correo de Apache. Acción hoy: 1. Actualiza Tomcat y deshabilita o configura bien EncryptInterceptor si no lo usas. 2. Revisa clusters con sesión replicada por riesgo de encadenamiento. 3. Monitorea accesos al manager y patrones de requests raros. Tienes nodos de Tomcat expuestos con el interceptor de cifrado activo? Más contenido como este en @Soy_Nube_Negra. #Tomcat #Apache https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly

    Post summary

    The tweet announces CVE-2026-34486 for Apache Tomcat, describes how the EncryptInterceptor can be abused, confirms a patch is available, and urges users to update or disable the feature.

    0000054
    1.9K followersView on X
  • TuxCare@TuxCare_
    Disclosure

    🔓 Apache Tomcat admins: CVE-2025-24813 lets unauthenticated attackers pull off remote code execution, but only under specific (and surprisingly common) configurations. 👇 Here's what's affected, how the exploit actually works, and mitigation steps: https://tuxcare.com/blog/apache-tomcat-cve-2025-24813/?utm_campaign=Organic%20Social%20Blogs&utm_source=twitter&utm_medium=social&utm_term=blogpromo https://t.co/1OyIAlZshW

    Post summary

    The tweet announces CVE‑2025‑24813, describes its RCE impact under common Tomcat configurations, provides a link to detailed exploit mechanisms and mitigation, but offers no evidence of active exploitation or a ready‑made PoC tool.

    0000081
    1.2K followersView on X
  • Monster@meowxnstr
    Active Exploitation

    ⚠️ Apache Tomcat CVE-2025-24813 is being actively exploited — 30 hours after PoC release. Remote code execution via partial PUT + Java deserialization. Affects Tomcat 9.x, 10.x, 11.x — millions of servers. Patch now: → 9.0.99 → 10.1.35 → 11.0.3 Can't patch yet? Disable…

    Post summary

    CVE‑2025‑24813, affecting Tomcat 9‑11, is already being exploited in the wild after a PoC release; patches are available for affected versions.

    0000023
    3 followersView on X
  • HackerNoon | Learn Any Technology@hackernoon
    General

    Security failures don’t start with CVE disclosure. This case study of CVE-2025-24813 shows why routine upgrades, not alerts, determine outcomes. - https://hackernoon.com/security-doesnt-start-with-cve-disclosure #securitylifecyclemanagement #cve

    Post summary

    The tweet uses CVE‑2025‑24813 as a case study to argue that routine upgrades, rather than alerts, determine security outcomes, without providing technical or exploit details.

    00000210
    89.6K followersView on X
CPE platform detail49 entries

49 of 49 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
OSdebiandebian_linux11.0--
OSnetappbootstrap_os---
HWnetapphci_compute_node---

Explore more