References https://www.dell.com/support/kbdoc/zh-cn/000206114/idpa-apache-tomcat-%E9%BB%98%E8%AE%A4%E5%AE%89%E8%A3%85%E7%9A%84%E5%AE%89%E5%85%A8%E6%BC%8F%E6%B4%9E https://f002.backblazeb2.com/file/sec-news-backup/files/writeup/blog.heysec.org/_archives_980/index.html https://wh0ale.github.io/2018/12/23/2018-12-23-%E5%88%A9%E7%94%A8Tomcat%20Manager%E7%9A%84%E5%A4%9A%E7%A7%8D%E6%96%B9%E6%B3%95/ https://www.anquanke.com/post/id/223002 https://www.fortiguard.com/cn/outbreak-alert/apache-tomcat-rce https://zhuanlan.zhihu.com/p/655558858 https://www.hkcert.org/tc/security-bulletin/apache-tomcat-remote-code-execution-vulnerability_20250312 https://www.cnblogs.com/Junglezt/p/18122284 https://www.ujcms.com/articles/63304506924591617.html https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/middleware/Tomcat8-%E5%BC%B1%E5%8F%A3%E4%BB%A4+%E5%90%8E%E5%8F%B0getshell%E6%BC%8F%E6%B4%9E.md https://onsecurity.io/article/pentest-files-tomcat-rce-2/ https://forum.greenbone.net/t/tomcat-admin-default-credentials-script-is-not-working-anymore/9371 https://www.cobalt.io/vulnerability-wiki/inf1/network-weak-default-credentials-for-tomcat https://www.linkedin.com/posts/redteamworld_apache-tomcat-default-manager-credentials-activity-7419664797773934593-MGPA https://www.acunetix.com/vulnerabilities/web/apache-tomcat-insecure-default-administrative-password/ https://medium.com/@24bkdoor/is-this-tomcat-a-weakling-apache-3c9ac6ef0b54 https://tomcat.apache.org/security-10.html https://nvd.nist.gov/vuln/detail/cve-2026-29145 https://www.upwind.io/feed/apache-tomcat-vulnerability-cve-2025-24813-exposes-servers-to-rce-risks https://www.zscaler.com/blogs/security-research/cve-2025-24813-apache-tomcat-vulnerable-rce-attacks
Related VulnerabilitiesPoCCVE-2026-50229: Apache Tomcat - Cross-Site ScriptingPoCCVE-2026-34486: Apache Tomcat Tribes EncryptInterceptor Bypass - Remote Code ExecutionPoCCVE-2023-45648: Apache Tomcat - HTTP Request SmugglingPoCCVE-2022-34305: Apache Tomcat Examples Web Application - Cross-Site ScriptingApache Tomcat URL重写绕过漏洞 (CVE-2025-55752)Apache Tomcat 存在路径遍历漏洞(CVE-2025-55752)CVE-2025-24813 Apache Tomcat 远程代码执行漏洞tomcat-default-login: Apahce Tomcat Manager Default LoginPoCCVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of ServicePoCCVE-2000-0760: Jakarta Tomcat 3.1 and 3.0 - Information DisclosurePoCCVE-2007-2449: Apache Tomcat 4.x-7.x - Cross-Site ScriptingCVE-2016-8735: Apache Tomcat - Remote Code Execution via JMX Ports