logo

CVE-2025-24813: Critical Apache Tomcat Flaw Exposed

ID: f5e3dc76-fe34-5928-a765-29783dd6b471

STIX ID: report--f5e3dc76-fe34-5928-a765-29783dd6b471

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2026-02-19

Date Updated: 2026-07-16

...
...

Apache Tomcat is affected by CVE-2025-24813, a critical flaw in the partial PUT handling that can enable unauthenticated remote code execution, information disclosure, and file corruption across Tomcat 9.0.0-M1–9.0.98, 10.1.0-M1–10.1.34, and 11.0.0-M1–11.0.2; CERT NZ warns of PoC availability and active exploitation and urges immediate upgrades to patched releases (9.0.99+, 10.1.35+, 11.0.3+) or temporary mitigations such as disabling partial PUT and tightening write permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.