Years-Old Vulnerable Apache Struts 2 Versions See 387K Weekly Downloads
ID: 77c7f646-13bf-5a8e-ba6c-e38f9f009d40
STIX ID: report--77c7f646-13bf-5a8e-ba6c-e38f9f009d40
Feed Name: HackRead
Threat Score
**Executive summary:** Sonatype researchers disclosed CVE-2025-68493, a CVSS 8.8 vulnerability in Apache Struts XWork that allows crafted XML input to induce an infinite-loop denial-of-service; over 387,000 downloads occurred in one week with 98% being End-of-Life vulnerable versions while only ~1.8% downloaded the patched 6.1.1, creating widespread exposure and an urgent need for updates though no active exploitation is reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
