ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)
The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploited in the wild, posing a serious risk to organizations relying on Struts for their web applications. The threat actors are leveraging this flaw to deploy malicious payloads and gain unauthorized access to systems.
The SANS Internet Storm Center’s latest Stormcast identified a rapidly escalating threat centered around a critical vulnerability within Apache Struts 2. The vulnerability, tracked as CVE-2026-3853, stems from a deserialization flaw that can be exploited to execute arbitrary code on vulnerable servers. The ISC noted that this issue is currently being actively exploited in the wild, with threat actors targeting organizations using Struts 2. The vulnerability allows attackers to craft malicious requests that, when processed by Struts, will trigger a deserialization attack, leading to remote code execution. The ISC emphasized the urgency of addressing this issue due to the ease with which it can be exploited and the potential for widespread impact.