CVE-2025-68493

High PUBLISHED

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

Apache Software Foundation · Apache Struts

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.1 High EPSS 23.1%

At a Glance

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

apache
CVE Published
Jan 11, 2026
Exploitation Reported
Jul 20, 2026
CVSS
8.1 High
EPSS
23.1%
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Red Hat
Red Hat Enterprise Linux 8

javapackages-tools:201801/google-guice

All versions (default: unaffected)

Unaffected
Red Hat
Red Hat Fuse 7

struts2-core

All versions (default: affected)

Affected
Red Hat
Red Hat JBoss Enterprise Application Platform 8

struts2-core

All versions (default: unaffected)

Unaffected
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack

struts2-core

All versions (default: unaffected)

Unaffected
Apache Software Foundation
Apache Struts

com.opensymphony:xwork

2.0.0 to < 2.2.1

Affected
Apache Software Foundation
Apache Struts

org.apache.struts.xwork:xwork-core

2.2.1 to <= 6.1.0

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.