logo

Critical security hole in Apache Struts under exploit

ID: 1b2d089a-ee88-5012-ba60-9c20cd6f25f8

STIX ID: report--1b2d089a-ee88-5012-ba60-9c20cd6f25f8

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-12-17

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical Apache Struts 2 vulnerability (CVE-2024-53677, CVSS 9.5) affecting multiple Struts branches permits attackers to manipulate file upload parameters and perform path traversal through the deprecated File Upload Interceptor, enabling malicious file uploads and potential remote code execution. Public PoC code is available and researchers report active exploitation attempts; maintainers and advisories strongly recommend upgrading to Struts 6.4.0 or later (or the latest supported version) to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.