CVE-2025-68493Disclosure(apache / struts)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611CWE-112

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • struts

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-16); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
struts

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-16: 2Mentions · 2026-03-24: 2Mentions · 2026-07-31: 1PoC Mentioned / Linked · 2026-07-31: 1Technical Details · 2026-02-16: 1Technical Details · 2026-07-31: 102-1603-2407-31
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-162
Disclosure1General1
2026-03-242
Disclosure1General1
2026-07-311
Disclosure1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-68493 - high 🚨 Apache Struts XWork - XML External Entity Injection > Apache Struts 2.0.0 < 2.2.1 and 2.2.1 <= versions <= 6.1.0 contain an XML external en... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-68493 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a high‑severity XML External Entity Injection vulnerability (CVE‑2025‑68493) in Apache Struts 2 affecting multiple versions, with a link for further details.

    0903452.0K
    1.3K followersView on X
  • Geng Yang@geng_zast
    General

    So far in Q1 2026, our AI agent has verified hundreds of previously undisclosed 0-days. That is the practical effect of closing the loop from finding to proof. One representative case in the CDM writeup is CVE-2025-68493 in Apache Struts. https://t.co/SbCl488WF8

    Post summary

    The tweet announces discovery of many zero‑days, including CVE‑2025‑68493 in Apache Struts, but offers no technical, exploit, or patch details.

    10010156
    46 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    So far in Q1 2026, http://ZAST.AI has identified and verified hundreds of previously undisclosed 0-days across web applications, software supply chain code, and IoT systems. One representative case in our CDM writeup is CVE-2025-68493 in Apache Struts. https://t.co/0C1ZlV0BgC

    Post summary

    The post announces the discovery of CVE-2025-68493 in Apache Struts and references a writeup, but it does not provide technical, exploit, or patch details.

    10000141
    33 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @Komodosec 🚨 CVE-2025-68493 is a high-severity XML External Entity (XXE) vulnerability (CVSS 8.1) in Apache Struts 2's XWork component. It stems from missing XML validation that allows attackers to process external entities in crafted XML input. #CVE2025 #ApacheStruts

    Post summary

    The tweet announces a high‑severity XXE vulnerability (CVE‑2025‑68493) in Apache Struts 2's XWork component, providing technical details and a CVSS score, but does not mention a PoC, exploit, or patch.

    1000038
    313 followersView on X
  • Komodo Cyber Security@Komodosec
    General

    #VulnerabilityReport #ApacheStruts2 The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data https://securityonline.info/the-xml-trap-critical-struts-2-flaw-cve-2025-68493-exposes-data/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet highlights a critical Struts 2 flaw (CVE‑2025‑68493) that can expose data but offers no further technical, exploit, or mitigation details.

    1000052
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestruts---

Explore more