Cyber Security News

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to remote code execution, denial-of- service, and unintended data disclosure.

Recommended fixes include Struts 7.4.0 or later, or Struts 6.12.0 or later for organizations using the 6.x maintenance line. The vulnerabilities affect different framework components, so exposure depends on application configuration and functionality.

Three issues carry a Moderate security rating, while an unrestricted request body issue in the REST plugin is rated Important. The supplied material does not establish active exploitation.

CVE-2026-104711 involves OGNL injection in the legacy RESTful action mapper. A crafted request can inject an expression that may lead to remote code execution when an application uses this mapper.

Apache documentation explains that the legacy mapper extracts action names and parameter values from request URLs. Affected releases include Struts 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.11.0. Struts 7.0.0 through 7.3.0 is affected only when the OGNL allowlist is disabled.

Applications using the default mapper, restful2 mapper, or Struts REST plugin are not affected by this specific flaw. Struts 7 retains protection in its default configuration. LeaveSong reported the issue.

CVE-2026-104712 allows small requests to generate disproportionately large responses. Exposure occurs when request parameters populate java.math.BigDecimal properties that are subsequently rendered through the Struts tag library.

Apache Struts Vulnerabilities

An unauthenticated attacker can use sustained, low-volume traffic to consume server CPU and outbound network capacity. Applications using other numeric types, or producing responses through the JSON or REST plugins, are outside the described exposure.

Affected versions are Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Reporter 0xCc.Zhang identified the flaw.

A temporary workaround uses a custom BigDecimal converter that bounds scale before rendering. Apache supports application-wide converter registration through struts-conversion.properties in the classpath root.

CVE-2026-104713 affects applications accepting request bodies through the optional REST plugin. The vulnerable implementation reads bodies into memory without a size bound, allowing a single oversized request to exhaust heap memory.

Affected versions span Struts 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Researcher n0mi1k reported the issue.

Fixed releases introduce a default limit of 2,097,152 characters. Organizations unable to upgrade should enforce request body limits at the reverse proxy or servlet container. The plugin handles incoming content representations, including XML and JSON.

CVE-2026-104714 concerns shared localized message formatters handling date or time arguments. Concurrent requests can interfere, causing one user’s value to appear in another user’s response or triggering rendering errors.

Reported by n0mi1k, it affects the listed Struts branches through 6.11.0 and 7.3.0. Ordinary concurrent traffic can trigger the problem without malicious input.

Administrators should upgrade affected deployments and review mapper settings, decimal rendering, REST endpoints, and localized messages. Formatting dates before message interpolation provides a temporary workaround for the formatter issue.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

14 minutes ago

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…

16 minutes ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

19 minutes ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

58 minutes ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

1 hour ago

Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure

Iranian state-aligned hackers have used a fake Dubai Airports recruitment process to target Iraqi critical…

2 hours ago