THREATOPS
THREAT OPSThreat News › Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation)

Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation)

medfulldisclosurePublished 2026-08-06

<p>Posted by disclosure via Fulldisclosure on Aug 06</p>0day Rubbish Research Team is publicly disclosing a vulnerability in Apache Struts 2 2.6.11.0 (Apache Software <br /> Foundation). The research is published and a proof-of-concept is available.<br /> <br /> Pre-authentication RCE (CVSS 9.8, pre-authentication)<br /> <br /> Apache Struts 2.6.11.0 is vulnerable to unauthenticated remote code ex

Indicators of compromise

Original source: https://seclists.org/fulldisclosure/2026/Aug/4