Apache Tomcat Global Footprint

Top 10 Identified Countries

Country Observations Percentage
US 193,688 23.60%
CN 178,177 21.71%
KR 47,731 5.82%
DE 35,204 4.29%
IN 32,053 3.91%
BR 31,412 3.83%
JP 23,416 2.85%
FR 17,543 2.14%
SG 16,107 1.96%
HK 15,035 1.83%

Is Apache Tomcat part of your extended attack surface? Bitsight helps security leaders rapidly identify exposure and detect threats in order to prioritize, communicate, and mitigate risk.

View interactive product tours

Apache Tomcat Industry Footprint

Top 10 Identified Industries

*Service provider organizations (typically Technology and Telecommunications) are disproportionally represented in the results given their upstream ownership of end-user infrastructure. See our FAQs.

Industry* Observations Percentage
Technology 427,422 74.39%
Telecommunications 104,667 18.22%
Education 12,109 2.11%
Government/Politics 7,602 1.32%
Business Services 4,404 0.77%
Finance 2,941 0.51%
Manufacturing 2,184 0.38%
Retail 1,717 0.30%
Transportation 1,618 0.28%
Healthcare/Wellness 1,550 0.27%

Tomcat Version Details

530 Versions Found
Version Number of Observations Sort ascending
9.0.46 1,098
8.5.84 1,091
7.0.62 1,090
6.0.36 1,078
9.0.45 1,069
8.5.23 1,068
8.5.63 1,054
7.0.53 1,048
10.1.44 1,030
6.0.29 1,026

Tomcat CVEs

Top 10 CVEs
CVE Number Number of Observations
CVE-2025-24813 164,482
CVE-2025-61795 89,923
CVE-2025-55752 87,631
CVE-2025-48989 85,577
CVE-2025-52520 81,697
CVE-2025-53506 81,697
CVE-2025-55668 81,217
CVE-2023-46589 80,120
CVE-2025-49125 79,667
CVE-2025-48988 79,667

Bitsight, the leading provider in Cyber Risk Management, introduced the next-generation internet scanner Bitsight Groma in May 2024. This technology continuously scans the entire internet to discover assets, collect asset attribution evidence, and identify an ever-growing set of security observations, such as vulnerabilities and misconfigurations. Groma’s scanning activities presently encompass:


  • 40 million-plus monitored organizations
  • 250 million-plus host names
  • 4 billion-plus routable IPv4 and IPv6 addresses

Greynoise’s recent study testifies the speed of Bitsight Groma.

Bitsight data discovery
Governance charcoal background

Bitsight TRACE team investigates security incidents and identifies vulnerabilities and threats.

View latest security research 

See what you’re up against across the expanding attack surface. Prioritize what matters most. And mitigate where you’re most vulnerable.

External Attack Surface Management

Bitsight ASA Report Image

Reducing exposure starts with knowing exactly how your external attack surface stands—from your overall standing to each digital and cloud asset around the world. Bitsight's custom report gives you the insights you need to see your entire external attack surface.