logo

The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data

ID: 1d71bc16-5f0b-5718-820c-bb1b524c3b8b

STIX ID: report--1d71bc16-5f0b-5718-820c-bb1b524c3b8b

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical XML External Entity (XXE) vulnerability (CVE-2025-68493) was discovered in the XWork component of Apache Struts 2 that can lead to data disclosure, DoS, and SSRF; multiple Struts versions (including EOL branches) are affected and Apache recommends upgrading to Struts 6.1.1, with temporary mitigations available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.