Apache Struts Remote Code Execution Vulnerability

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

Published 2 Sep 2026Updated 2 Sep 2026175 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

Source timeline

Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗