The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data
ID: 1d71bc16-5f0b-5718-820c-bb1b524c3b8b
STIX ID: report--1d71bc16-5f0b-5718-820c-bb1b524c3b8b
Feed Name: securityonline.info
Threat Score
A critical XML External Entity (XXE) vulnerability (CVE-2025-68493) was discovered in the XWork component of Apache Struts 2 that can lead to data disclosure, DoS, and SSRF; multiple Struts versions (including EOL branches) are affected and Apache recommends upgrading to Struts 6.1.1, with temporary mitigations available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
