Skip to content
Critical Apache Struts 2 Vulnerability CVE-2025-68493 Exposes Sensitive Data

Critical Apache Struts 2 Vulnerability CVE-2025-68493 Exposes Sensitive Data

First seen 12 Jan 2026, 14:42 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical XML external entity (XXE) injection vulnerability, tracked as CVE-2025-68493, has been identified in Apache Struts 2. This flaw affects multiple versions of the framework, potentially exposing millions of applications to data theft and server compromise. Immediate action is required from developers and system administrators to mitigate the risks associated with this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (7)

Following this threat?

Track CVE-2025-68493 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed