Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces
  • Vulnerability Report

Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces

Do Son June 13, 2025 2 minutes read
0
Apache Tomcat, Brute-Force Attacks CVE-2024-38286 - Apache Tomcat 11
Add Daily CyberSecurity as a preferred source on Google

A significant surge in brute-force attacks is targeting Apache Tomcat Manager interfaces, according to a new report from GreyNoise. On June 5, 2025, analysts observed a large-scale campaign where attackers attempted to guess login credentials, clearly aiming to compromise publicly exposed Tomcat services.

Running Infra, AppSec, and SOC teams? Tag Apache alerts by team automatically.

Try Team free for 14 days →

On that single day, 295 unique malicious IP addresses were detected engaging in brute-force attacks against Tomcat Manager. In the following 24 hours, another 188 unique malicious IPs were active. These attacks primarily originated from the United States, United Kingdom, Germany, the Netherlands, and Singapore.

Simultaneously, 298 unique IP addresses (246 active within 24 hours) attempted logins to Tomcat Manager control panels, showing a similar geographical distribution. Additional targeted countries in this attack wave included Spain, India, and Brazil. A large portion of the malicious traffic was traced back to infrastructure hosted by DigitalOcean.

While these attacks aren’t tied to a specific software vulnerability, they highlight a persistent interest in unprotected Tomcat access. This widespread, opportunistic activity often signals the early stages of more coordinated and targeted exploitation campaigns in the future.

GreyNoise urges administrators of publicly exposed Tomcat Manager instances to take immediate action: enforce strong authentication, strengthen access controls, and vigilantly monitor for any suspicious activity.

Related Posts:

  • Google Account Flaw Exposed Phone Numbers: Brute-Force Attack Possible, Now Patched
  • Data at Risk: Three-Quarters of Top Websites Leave Users Exposed to Cyberattacks
  • Tomcat Flaw CVE-2025-24813 Exploited in the Wild, PoC Released
  • CVE-2025-24813 Flaw in Apache Tomcat Exposes Servers to RCE, Data Leaks: Update Immediately
  • CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS

Related coverage

  • Critical IBM MQ Vulnerabilities CVE-2026-10747 Hit 10 CVSS
  • Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE
  • Critical Defect Exposed: Flaw In Apache Fory Bypasses Deserialization Protections
  • Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover
  • Google Rolls Out Chrome 142 Patching 20 Security Flaws
  • OpenSSH Flaw (CVE-2025-61984) Allows Remote Code Execution via Usernames
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: apache Tomcat Brute Force cyberattack cybersecurity DigitalOcean GreyNoise Login Attempts Tomcat Manager Web Security web server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105763CVSS 9.6
    Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query...
    📅 Updated: Oct 6, 2026
  • CVE-2025-12543CVSS 9.6
    A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and...
    📅 Updated: Oct 6, 2026
  • CVE-2026-90711CVSS 9.1
    ### Impact `proxy-addr` determines which network hops are trusted proxies so that `X-Forwarded-For` can be believed. When an...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100721CVSS 10.0
    ## Summary At source revision `91034466bfb7f56b95fd48083ec6ca36d058f164` of vm2 3.11.8, an untrusted `NodeVM` guest can turn one allowlisted custom-resolved...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100723CVSS 10.0
    ## Summary When an application explicitly exposes Node's `zlib` module through vm2's `NodeVM` builtin allowlist, an untrusted guest...
    📅 Updated: Oct 5, 2026
  • CVE-2026-85394CVSS 9.1
    python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack...
    📅 Updated: Oct 5, 2026
  • CVE-2026-92955CVSS 10.0
    ## Summary It being possible to obtain the host `__proto__` getter/setter, has been used in many reports: -...
    📅 Updated: Oct 5, 2026
  • CVE-2026-92953CVSS 10.0
    ## Summary vm2's current host-intrinsic prototype protection is incomplete. The fix for `GHSA-vwrp-x96c-mhwq` blocks sandbox writes into classic...
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.