Apache Struts — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 20, 2025
Last Seen
June 17, 2026

Apache Struts is a widely used open-source Java-based web application framework that powers many enterprise websites and services.

Overview

Apache Struts is a widely used open-source Java-based web application framework that powers many enterprise websites and services. Recent reports describe a vulnerability in Struts that can be exploited to trigger disk exhaustion on affected servers, creating a denial-of-service risk for organizations relying on Struts-based apps.

Related Threat Clusters

  • Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks

    A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…

    16 articles · Updated March 26, 2026
  • Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited

    Atlassian Confluence has faced multiple critical vulnerabilities, including CVE-2022-26134 and CVE-2023-22515. CVE-2022-26134, published on June 3, 2022, is an unauthenticated remote code execution vulnerability that…

    3 articles · Updated June 17, 2026
  • New CVSS 10.0 Vulnerability CVE-2026-29000 Discovered

    A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…

    2 articles · Updated March 6, 2026
  • APT41 Cyber-Espionage Tactics Explored in Ransomware Emulations

    The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…

    14 articles · Updated January 6, 2026
  • Apache Struts Vulnerability Enables Disk Exhaustion Attacks

    A vulnerability in Apache Struts has been identified, allowing attackers to execute disk exhaustion attacks. This flaw poses risks to systems using the affected version of Apache Struts, potentially leading to service…

    4 articles · Updated December 2, 2025

Recent Intelligence Reports

  • Rapid7 Analysis: CVE-2023 — Rapid7 · June 17, 2026
  • China-linked hackers plant stealth malware deep in global telecom networks: Report — Thehansindia · March 27, 2026
  • China-linked hackers plant stealth malware deep in global telecom networks: Report — Lokmattimes · March 27, 2026
  • Why CVSS 10 Vulnerabilities Are So Dangerous (Real Examples) — Codeant.Ai · March 6, 2026
  • Apache Struts Vulnerability Lets Attackers Trigger Disk Exhaustion Attacks — Cyberpress · December 2, 2025
  • Apache Struts Vulnerability Let Attackers Trigger Disk Exhaustion Attacks — Cybersecuritynews · December 2, 2025
  • Apache Struts Vulnerability Let Attackers Trigger Disk Exhaustion Attacks — Cybersecuritynews · December 2, 2025
  • Apache Struts Flaw Allows Attackers to Launch Disk Exhaustion Attacks — Gbhackers · December 2, 2025

CVSS v3.1 Breakdown