vulns.coMCP

← CVE intelligence

CVE-2016-3081 - Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Severity
critical
Product
Apache Struts
Published
2026-10-08
EPSS
0.934
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.