Critical Apache Struts 2 Vulnerability CVE-2025-68493 Exposes Sensitive Data

Critical Apache Struts 2 Vulnerability CVE-2025-68493 Exposes Sensitive Data

First seen 12 Jan 2026, 14:42 UTC GbhackersRedhotcyberCyberpressCybersecuritynewsSecurityboulevard+2 30.1

Article Content

Browse articles
ThreatCluster

A critical XML external entity (XXE) injection vulnerability, tracked as CVE-2025-68493, has been identified in Apache Struts 2. This flaw affects multiple versions of the framework, potentially exposing millions of applications to data theft and server compromise. Immediate action is required from developers and system administrators to mitigate the risks associated with this vulnerability.