Critical Apache Struts 2 Vulnerability Allow Attackers to Steal Sensitive Data
ID: 7746a8b9-a18a-5650-8143-cccf844be155
STIX ID: report--7746a8b9-a18a-5650-8143-cccf844be155
Feed Name: cybersecurityNews.com
**Apache Struts 2 XXE Vulnerability (CVE-2025-68493):** A critical XML External Entity injection flaw in the XWork component of Apache Struts 2 affects multiple version ranges (2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.1.0); successful exploitation can lead to data disclosure, SSRF and DoS. Apache released Struts 6.1.1 as the fixed version and organizations are advised to upgrade immediately or apply temporary mitigations (custom SAXParserFactory or JVM properties disabling external entities).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
