Alert: Apache Tomcat Security Updates – October 2025
The Apache Software Foundation released security updates to address multiple vulnerabilities in the Apache Tomcat, including a critical directory traversal flaw that can lead to remote code execution (RCE).
Affected Systems:
The affected systems and versions include, but are not limited to:
Please refer to the official Apache Software Foundation website for a complete list of the security patches that have been released.
Security Risks
The successful exploitation of vulnerabilities in Apache software poses a significant security risk, allowing cybercriminals to escalate privileges, execute arbitrary code, and disrupt or compromise the affected systems.
Recommended Actions
The National Cyber Security Authority (NCSA) strongly recommends that system administrators:
The released software versions for upgrade include, but are not limited to:
References
29 October 2025
More updates
© 2025 National Cyber Security Authority