logo

Apache Tomcat RCE Vulnerability Under Fire With 2-Step Exploit

ID: 02210374-748e-5e10-b1d0-0f71177bc7ea

STIX ID: report--02210374-748e-5e10-b1d0-0f71177bc7ea

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-03-17

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

A critical remote code execution vulnerability in Apache Tomcat (CVE-2025-24813) is being actively exploited in the wild: attackers upload a serialized Java session via a PUT request and trigger deserialization with a subsequent GET, enabling server takeover. The bug (Red Hat score 8.6) requires no authentication, commonly bypasses WAFs due to base64 encoding and the two-step flow, and was first observed in attacks on March 12; researchers recommend deep, real-time API analysis and blocking multi-step/obfuscated payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.