logo

RCE Vulnerability in Apache Struts Targeted by Attackers (Campaign)

ID: a50395ad-1589-5e5a-a53f-b1ed1c8034b1

STIX ID: report--a50395ad-1589-5e5a-a53f-b1ed1c8034b1

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-12-17

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

CVE-2024-53677 is a critical Apache Struts 2 file-upload vulnerability (CVSS 9.5) that permits path traversal and the upload of malicious files such as web shells, enabling remote code execution; active exploitation has been observed in the wild using public proof-of-concept exploits to enumerate and confirm vulnerable servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.