CVE-2016-3081

Confirmed PUBLISHED

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to...

Apache · Struts

Not yet in CISA KEV

Exploited in the wild Active exploitation observed PoC available

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
40
Unique Attacker IPs
21
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.1 High EPSS 93.2%

At a Glance

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

apache
CVE Published
Apr 26, 2016
Exploitation Reported
Jun 27, 2026
CVSS
8.1 High
EPSS
93.2%
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 39756 exploit-db.com · Exploit https://www.exploit-db.com/exploits/39756/
  • 1035665 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1035665
  • 91787 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/91787
  • 87327 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/87327
  • struts.apache.org/docs/s2-032.html struts.apache.org · CVE Record https://struts.apache.org/docs/s2-032.html
Show 6 more references

Recommended Actions

  • Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.
  • Review sensor telemetry for request paths, attacker IPs, and payload patterns that may inform detection and exposure validation.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.