Vulnerability
Published 2026-10-08
Verified 2026-10-08

Apache Struts (CVE-2016-3081)

Apache Struts Command Injection Vulnerability. Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

Product
Apache Struts
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2016-3081

vulnerabilities