Apache Released Updates for Four Struts Vulnerabilities

The security patches address critical flaws across multiple versions of the popular framework.

Updated on Oct. 6, 2026 in Cybersecurity

Isometric editorial illustration of a secure industrial server cabinet, representing software framework integrity.
Apache released security updates in August 2026 to address four critical vulnerabilities in its Struts framework, including risks of remote code execution. AI Illustration. Upload story photo >

Live Poll

Do you trust that software providers adequately maintain security for their older legacy products?

Apache released security updates in August 2026 to resolve four distinct vulnerabilities found within the Struts framework. These flaws previously exposed applications to risks including remote code execution, denial of service, and unauthorized data disclosure.

Why it matters

The vulnerabilities stem from specific flaws in legacy action mapping, decimal rendering, REST request processing, and localized message formatting. Addressing these weaknesses is essential for maintaining the integrity and security of software systems that rely on the Struts platform.

The security updates were integrated into Struts versions 7.4.0 and 6.12.0. These patches specifically target vulnerabilities within legacy action mapping, decimal rendering, REST request processing, and localized message formatting.

The players

Apache Software Foundation

The Apache Software Foundation is a non-profit corporation that provides support for the Apache community of open-source software projects.

The details

The vulnerabilities were identified as significant security risks, allowing for remote code execution and cross-user data disclosure. Developers are encouraged to update their frameworks to versions 7.4.0 or 6.12.0 to mitigate the threat of service disruption and data exposure.

Timeline

  1. August 2026: Advisories regarding the four vulnerabilities were published.

The Tech Race

This release follows the established patterns seen in the Apache Struts security maintenance lifecycle for managing critical framework flaws. It reflects the ongoing industry necessity of patching legacy codebases to defend against remote execution threats in an evolving digital landscape.

Users and developers should verify their current framework version to ensure they are protected against potential remote code execution. Failure to patch these vulnerabilities leaves systems susceptible to data disclosure and denial of service attacks.

The takeaway

Maintaining up-to-date framework versions is a fundamental practice in preventing unauthorized system access. Developers should prioritize scanning their environments for legacy Struts implementations to apply the necessary security patches.

Further reading

Stay updated on framework risks and remediation by visiting the Cybersecurity section.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you trust that software providers adequately maintain security for their older legacy products?