CVE-2025-55754
Other Console (ANSI Injection)
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.
Ransomware groups exploiting CVE-2025-55754
Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, he
Exploitation is attributed to these groups across their recorded activity. It does not follow that every organisation they listed was reached through CVE-2025-55754 — the source data does not record an entry point per incident.
Exploitation status
EPSS — exploitation probability
FIRST puts the probability of exploitation activity in the next 30 days at 10.1%, which is higher than 95.2% of all scored vulnerabilities. EPSS is a forecast of activity, not a measure of severity, and it is rescored daily.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Recent listings by these groups
Disclosures from the groups above, newest first.
Frequently asked questions
Is CVE-2025-55754 being exploited by ransomware groups?
Yes. CVE-2025-55754 is recorded as exploited by Tengu. Between them these groups account for 49 victim disclosures in this database.
What does CVE-2025-55754 affect?
CVE-2025-55754 affects Other Console (ANSI Injection). Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.
How severe is CVE-2025-55754?
CVE-2025-55754 is rated CRITICAL with a CVSS base score of 9.6. EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95.2% of all scored vulnerabilities. It is not currently in the CISA Known Exploited Vulnerabilities catalog.
How should organisations respond to CVE-2025-55754?
Apply the vendor patch for Other Console (ANSI Injection) as the first priority, and treat any internet-facing instance as the most urgent. Because this vulnerability is associated with ransomware activity, also review whether the affected systems were reachable before patching, rather than assuming that patching alone closes the incident.