Post cover image

June 3, 2026

Ghostcat-PWN: When an Old Tomcat Vulnerability Opens the org doors

From exposed AJP connectors to reliable post-exploitation workflows: the story behind Ghostcat-PWN and our experience with CVE-2020–1938

Deepanshu khanna

19 min read