Redhotcyber
Critical Apache Struts 2 Vulnerability CVE-2025-68493 Exposes Sensitive Data
First seen 12 Jan 2026, 14:42 UTC
•



+2
•30.1
Export
Article Content
Browse articles
A critical XML external entity (XXE) injection vulnerability, tracked as CVE-2025-68493, has been identified in Apache Struts 2. This flaw affects multiple versions of the framework, potentially exposing millions of applications to data theft and server compromise. Immediate action is required from developers and system administrators to mitigate the risks associated with this vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.