Skip to content
September 15, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces
  • Vulnerability Report

Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces

Do Son June 13, 2025 2 minutes read
0
Apache Tomcat, Brute-Force Attacks CVE-2024-38286 - Apache Tomcat 11
Add Daily CyberSecurity as a preferred source on Google

A significant surge in brute-force attacks is targeting Apache Tomcat Manager interfaces, according to a new report from GreyNoise. On June 5, 2025, analysts observed a large-scale campaign where attackers attempted to guess login credentials, clearly aiming to compromise publicly exposed Tomcat services.

Track every Apache CVE the moment it's exploited.

Get free email alerts →

On that single day, 295 unique malicious IP addresses were detected engaging in brute-force attacks against Tomcat Manager. In the following 24 hours, another 188 unique malicious IPs were active. These attacks primarily originated from the United States, United Kingdom, Germany, the Netherlands, and Singapore.

Simultaneously, 298 unique IP addresses (246 active within 24 hours) attempted logins to Tomcat Manager control panels, showing a similar geographical distribution. Additional targeted countries in this attack wave included Spain, India, and Brazil. A large portion of the malicious traffic was traced back to infrastructure hosted by DigitalOcean.

While these attacks aren’t tied to a specific software vulnerability, they highlight a persistent interest in unprotected Tomcat access. This widespread, opportunistic activity often signals the early stages of more coordinated and targeted exploitation campaigns in the future.

GreyNoise urges administrators of publicly exposed Tomcat Manager instances to take immediate action: enforce strong authentication, strengthen access controls, and vigilantly monitor for any suspicious activity.

Related Posts:

  • Google Account Flaw Exposed Phone Numbers: Brute-Force Attack Possible, Now Patched
  • Data at Risk: Three-Quarters of Top Websites Leave Users Exposed to Cyberattacks
  • Tomcat Flaw CVE-2025-24813 Exploited in the Wild, PoC Released
  • CVE-2025-24813 Flaw in Apache Tomcat Exposes Servers to RCE, Data Leaks: Update Immediately
  • CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS

Related coverage

  • EchoLeak: First AI Zero-Click Vulnerability Leaks Data from Microsoft 365 Copilot
  • Sabotage & Exploited in the Wild: Critical Backdoor Found in LA-Studio Element Kit
  • HPE Aruba Patches High-Severity RCE and OpenSSL Flaws
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: apache Tomcat Brute Force cyberattack cybersecurity DigitalOcean GreyNoise Login Attempts Tomcat Manager Web Security web server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-19773CVSS 9.8
    libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability....
  • CVE-2026-12351CVSS 9.8
    IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through...
  • CVE-2024-58385CVSS 9.8
    Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php...
  • CVE-2023-54398CVSS 9.8
    Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet...
  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit...
  • CVE-2026-91949CVSS 9.3
    FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that...
  • CVE-2026-63696CVSS 9.1
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of...
  • CVE-2026-63695CVSS 9.8
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation...
  • CVE-2026-39919CVSS 9.8
    Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG...
  • CVE-2026-91998CVSS 9.9
    Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.