New critical Apache Struts flaw exploited to find vulnerable servers
ID: 0ed49eba-6e40-5b92-8f3f-47d9303bd006
STIX ID: report--0ed49eba-6e40-5b92-8f3f-47d9303bd006
Feed Name: Bleeping Computer
Apache disclosed CVE-2024-53677, a critical (CVSS 9.5) Struts 2 file-upload vulnerability allowing path traversal and remote code execution via uploaded web shells; public PoCs are being used in active exploit attempts (uploading an exploit.jsp for verification), at least one attacking IP (169.150.226.162) has been observed, and multiple national cybersecurity agencies have issued alerts urging affected users to upgrade to Struts 6.4.0+ and migrate to the new Action File Upload mechanism.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
