A critical remote code execution vulnerability (CVE-2026-41321) in Apache Struts has been discovered actively exploited in the wild. The flaw, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary commands on affected servers through crafted Content-Type headers. Apache has released Read more…