logo

Orgs Scramble to Fix Actively Exploited Bug in Apache Struts 2

ID: 05fccebd-9edd-5b35-b129-847ca61bd7c1

STIX ID: report--05fccebd-9edd-5b35-b129-847ca61bd7c1

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-12-19

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Apache Struts 2 is affected by a critical RCE vulnerability (CVE-2024-53677, CVSS 9.5) in the File Upload Interceptor that enables path traversal and remote code execution; public PoCs and observed exploitation attempts have been reported, remediation requires migrating to a new Action File Upload Interceptor with code changes rather than a simple patch, and tens of thousands of vulnerable instances were observed, prompting warnings from multiple national cybersecurity centers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.