logo

Critical Apache Struts 2 Vulnerability Allow Attackers to Steal Sensitive Data

ID: 7746a8b9-a18a-5650-8143-cccf844be155

STIX ID: report--7746a8b9-a18a-5650-8143-cccf844be155

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Apache Struts 2 XXE Vulnerability (CVE-2025-68493):** A critical XML External Entity injection flaw in the XWork component of Apache Struts 2 affects multiple version ranges (2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.1.0); successful exploitation can lead to data disclosure, SSRF and DoS. Apache released Struts 6.1.1 as the fixed version and organizations are advised to upgrade immediately or apply temporary mitigations (custom SAXParserFactory or JVM properties disabling external entities).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.