Apache Struts 1 Improper Input Validation Vulnerability

The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

Published 15 Sep 2026Updated 15 Sep 202613 sources
CVSS 9.8 ✓ VERIFIED REFERENCE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.