CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2025-24813: Apache Tomcat Remote Code Execution Vulnerability

June 25, 2026

CVE-2025-24813 is a remote code execution flaw in Apache Tomcat disclosed in March 2025 and added to CISA's Known Exploited Vulnerabilities catalog. It allows attackers to execute arbitrary code on unpatched servers, potentially leading to credential theft and lateral movement.