Sunday, 16 August, 2026

Critical Zero-Day in Apache Struts Exploited in the Wild — Patch Immediately


A critical remote code execution vulnerability (CVE-2026-41321) in Apache Struts has been discovered actively exploited in the wild. The flaw, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary commands on affected servers through crafted Content-Type headers.

Apache has released version 6.4.1 to address the vulnerability. Organizations running Apache Struts are strongly advised to patch immediately. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a remediation deadline of September 1, 2026.

Affected Versions

  • Apache Struts 2.0.0 through 6.4.0
  • Apache Struts 6.3.x (all versions)

Indicators of Compromise

Security teams should monitor for unusual POST requests with malformed Content-Type headers targeting Struts action endpoints. Detailed IOCs are available in the Apache advisory.

0 comments on “Critical Zero-Day in Apache Struts Exploited in the Wild — Patch Immediately

Leave a Reply

Your email address will not be published. Required fields are marked *