logo

ACSC Warns Of Remote Code Execution In Apache Struts2

ID: 4ecb301f-e0d5-558b-b1e5-7d64b4c34390

STIX ID: report--4ecb301f-e0d5-558b-b1e5-7d64b4c34390

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-12-16

Date Updated: 2026-07-16

...
...

**Executive summary:** CVE-2024-53677 is a critical file upload/path traversal vulnerability in Apache Struts2 (CVSSv3 9.8) affecting multiple Struts branches; successful exploitation can allow remote code execution via uploaded malicious files, so organizations should upgrade to Struts 6.4.0 or apply available patches, audit use of the deprecated File Upload Interceptor, and increase monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.