logo

Critical Apache Struts 2 Flaw Could Let Attackers Steal Sensitive Data

ID: b42ba569-0b69-5920-9a35-04e5a633b1c1

STIX ID: report--b42ba569-0b69-5920-9a35-04e5a633b1c1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** A newly disclosed Important-severity XXE vulnerability (CVE-2025-68493) in Apache Struts 2's XWork component can allow attackers to read local files, perform SSRF, and cause DoS; it affects many Struts 2 branches and users are urged to upgrade to Struts 6.1.1 or apply XML parsing hardening mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.