Apache Struts: known exploited vulnerabilities
Entries6
Ransomware-linked1
First added2021-11-03
Latest2026-10-08
EPSS compared
99.9%
99.9%
99.9%
99.3%
95.9%
93.3%
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2016-3081 | Apache Struts | 2026-10-08 | 93.3% | Unknown |
| CVE-2013-2251 | Apache Struts | 2022-03-25 | 99.9% | Unknown |
| CVE-2020-17530 | Apache Struts | 2021-11-03 | 95.9% | Unknown |
| CVE-2018-11776 | Apache Struts | 2021-11-03 | 99.9% | Unknown |
| CVE-2017-9805 | Apache Struts | 2021-11-03 | 99.3% | Unknown |
| CVE-2017-5638 | Apache Struts | 2021-11-03 | 99.9% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.