logo

Years-Old Vulnerable Apache Struts 2 Versions See 387K Weekly Downloads

ID: 77c7f646-13bf-5a8e-ba6c-e38f9f009d40

STIX ID: report--77c7f646-13bf-5a8e-ba6c-e38f9f009d40

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Sonatype researchers disclosed CVE-2025-68493, a CVSS 8.8 vulnerability in Apache Struts XWork that allows crafted XML input to induce an infinite-loop denial-of-service; over 387,000 downloads occurred in one week with 98% being End-of-Life vulnerable versions while only ~1.8% downloaded the patched 6.1.1, creating widespread exposure and an urgent need for updates though no active exploitation is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.