<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle" -->

---
title: Critical Apache Tomcat Vulnerability CVE-2025-24813...
description: Apache Tomcat faces a critical remote code execution vulnerability identified as CVE-2025-24813, which is actively being exploited. This flaw, affecting...
canonical: https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Apache Tomcat Vulnerability CVE-2025-24813 Actively Exploited | daily.dev
og:description: Apache Tomcat faces a critical remote code execution vulnerability identified as CVE-2025-24813, which is actively being exploited. This flaw, affecting...
og:url: https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle
og:image: https://api.daily.dev/og/posts/qtnAByXle.png
og:image:alt: Critical Apache Tomcat Vulnerability CVE-2025-24813 Actively Exploited
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Apache Tomcat Vulnerability CVE-2025-24813 Actively Exploited

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Apache Tomcat faces a critical remote code execution vulnerability identified as CVE-2025-24813, which is actively being exploited. This flaw, affecting versions 9.0.0-M1 to 11.0.2, allows attackers to gain remote access using a straightforward method involving PUT requests. The severity of the vulnerability is rated 8.6 out of 10. Apache Tomcat users are urged to upgrade to patched versions 11.0.3 or later, 10.1.35 or later, 9.0.99 or later to mitigate the risks, along with implementing enhanced security practices.

## Content

Apache Tomcat is currently facing active attacks due to a critical remote code execution (RCE) vulnerability, identified as CVE-2025-24813. This flaw allows attackers to exploit servers using a straightforward method involving PUT requests. The simplicity of the attack has enabled rapid exploitation, just 30 hours after public disclosure, with reports indicating active abuse by various threat actors, including Chinese operators.

### Vulnerability Details
The CVE-2025-24813 vulnerability affects the following Apache Tomcat versions:
- **11.0.0-M1 to 11.0.2**
- **10.1.0-M1 to 10.1.34**
- **9.0.0-M1 to 9.0.98**

Attackers utilize a Base64-encoded payload which gets executed upon deserialization, granting remote access to the targeted servers. Furthermore, the vulnerability can also lead to information disclosure and content manipulation when exploited.

### Exploitation and Impact
The severity of this vulnerability has been rated 8.6 out of 10 by Red Hat. Exploitation does not require authentication, significantly increasing the risk. The method involves a two-step process using PUT and GET requests, which bypasses many Web Application Firewalls (WAFs) due to its simplicity and encoding techniques. The attacks have been particularly effective when Tomcat uses file-based session storage.

### Mitigation Steps
To mitigate the risks associated with CVE-2025-24813, it is strongly advised to upgrade to the following patched versions:
- **11.0.3 or later**
- **10.1.35 or later**
- **9.0.99 or later**

Administrators are also recommended to disable risky features, apply stronger security measures, and implement real-time API security measures to prevent such attacks.

### Advisory Alerts
CERT NZ has issued a critical advisory regarding this vulnerability, emphasizing the importance of immediate updates and enhanced security practices. Similarly, the Cybersecurity and Infrastructure Security Agency (CISA) has also raised warnings about the ongoing exploitation in the wild.

In conclusion, given the severity and the active exploitation of CVE-2025-24813, it is crucial for all Apache Tomcat users to update their systems without delay to protect against potential breaches and mitigate the associated risks.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cloud](https://daily.dev/tags/cloud), [#cyber](https://daily.dev/tags/cyber), [#devops](https://daily.dev/tags/devops)

[View this post on daily.dev](https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Apache Tomcat Vulnerability CVE-2025-24813 Actively Exploited","url":"https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle"},"datePublished":"2025-03-17T19:07:20.364Z","dateModified":"2025-03-19T08:40:57.245Z","description":"Apache Tomcat faces a critical remote code execution vulnerability identified as CVE-2025-24813, which is actively being exploited. This flaw, affecting...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/88edd1a8a991b2ddebe2a583aa04c714?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/88edd1a8a991b2ddebe2a583aa04c714?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-apache-tomcat-vulnerability-cve-2025-24813-actively-exploited-qtnabyxle","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cloud,cyber,devops","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Critical Apache Tomcat Vulnerability CVE-2025-24813 Actively Exploited"}]}
```

