news.mlab.sh
Back to the feed
vulnerability

ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)

Critical
Summary

The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploited in the wild, posing a serious risk to organizations relying on this widely used web application framework.

The SANS Internet Storm Center’s latest Stormcast focused on a rapidly escalating threat involving Apache Struts. The core issue stems from a deserialization vulnerability within the Struts framework, specifically related to how it handles certain input data. This allows attackers to craft malicious requests that, when processed, can execute arbitrary code on the server. The vulnerability is currently being actively exploited in the wild, with evidence of attacks targeting various organizations.

Researchers have identified a specific attack vector involving specially crafted XML payloads. The vulnerability is classified as CVE-2026-3654, a critical severity issue. The ISC noted that this vulnerability has been present for a considerable time, but recent activity indicates a surge in exploitation attempts.

Specifically, the vulnerability allows for remote code execution, meaning an attacker can gain control of a server without needing local access. The ISC recommends immediate action to mitigate the risk. The vulnerability is impacting versions 2.5.3 through 2.5.31.

Organizations should prioritize patching their Struts installations to the latest version, or applying available workarounds. The ISC also advises implementing input validation and sanitization to prevent malicious data from being processed.

This situation underscores the importance of staying current with security updates and proactively monitoring for exploitation attempts. The widespread use of Apache Struts means that a large number of organizations are potentially at risk, highlighting the need for vigilance and rapid response.

Read the full article at SANS Internet Storm Center