Product of Apache

Tomcat

As of , 6 Apache Tomcat vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2017-12617.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2017-12617Remote Code ExecutionApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
2CVE-2020-1938Improper Privilege ManagementApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2025-24813Path EquivalenceApache TomcatPatch this weekMetasploit module; EPSS 0.990.99
4CVE-2016-8735Remote Code ExecutionApache TomcatPatch this weekEPSS 0.900.90
5CVE-2017-12615on Windows Remote Code ExecutionApache TomcatPatch this weekRansomware use; EPSS 0.990.99
6CVE-2026-34486Missing Encryption of Sensitive DataApache TomcatPatch soon0.07

Added each year

1232022: 3320222023: 1120232024: nonenone20242025: 1120252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20223
20231
2024none
20251
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-34486 Apache TomcatEdited: description.
  2. CVE-2025-24813 Apache TomcatEdited: description.
  3. CVE-2025-24813 Apache TomcatEdited: notes.

Every change we recorded