A concerning development has emerged with the active exploitation of Apache Tomcat servers through the recently disclosed vulnerability, CVE-2025-24813.
This vulnerability allows attackers to potentially execute remote code (RCE) if successfully exploited.
The cybersecurity firm GreyNoise has identified multiple IPs involved in these attacks across several regions, highlighting the urgency for organizations to update their systems immediately.
CVE-2025-24813 is capable of enabling remote code execution, which poses significant risks to the security of systems running Apache Tomcat.
The good news is that the current exploitation seems limited to naive attackers using publicly available proof-of-concept (PoC) code.
However, this could be a precursor to more sophisticated attacks as the vulnerability becomes widely known.
GreyNoise has created a specific CVE-2025-24813 tag to help defenders track and respond to these malicious activities efficiently.
Since March 17, 2025, GreyNoise has detected four unique IPs attempting to exploit this vulnerability.
These attackers are using a partial PUT method to inject malicious payloads, which could lead to arbitrary code execution on vulnerable systems. The geographic distribution of these attempts highlights a diverse range of targets:
Given the seriousness of CVE-2025-24813 and the ongoing exploitation, organizations must take immediate action to secure their systems:
Organizations should assess their Apache Tomcat deployments urgently and apply patches to mitigate the risks associated with CVE-2025-24813.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
In mid-March 2025, Kaspersky researchers uncovered a sophisticated APT attack, dubbed Operation ForumTroll, which leveraged…
Researchers at QiAnXin XLab have uncovered a sophisticated Linux-based backdoor dubbed OrpaCrab, specifically targeting industrial…
A recent snag in Google's Chrome distribution process has left Windows users unable to install…
Security researchers have uncovered a new attack campaign by the North Korean state-sponsored APT group…
A critical vulnerability has been identified in NetApp's SnapCenter Server, affecting versions before 6.0.1P1 and…
In a significant development, cybersecurity firm Silent Push has identified nearly 200 unique command and…