CVE-2025-68493
Apache Software Foundation Apache Struts, Red Hat Enterprise Linux 8, Red Hat Fuse 7
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
- CVSS
- 8.1
- EPSS
- 37.1% 98.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.11