Threat reportVulnerabilityTL-2026-2982

Apache Struts Vulnerabilities Enable Remote Code Execution and Denial of Service (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714)

highPATCHED

Apache Struts Vulnerabilities Enable Remote Code Execution (TL-2026-2982), also tracked as S2-075, is a high-severity software vulnerability, first published 2026-10-06. It has no confirmed attribution, affects Apache Software Foundation Apache Struts (legacy RESTful action, references 4 CVEs (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713), maps to 4 MITRE ATT&CK techniques (T1059, T1190, T1499.003), and is covered by 9 detection rules and 8 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
4Referenced vulnerabilities
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-2982

Threat ID
TL-2026-2982
Also known as
S2-075, S2-076, S2-077, S2-078
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, government administration, telecoms, health
Target regions
Global
Detection rules
9
Indicators of compromise
8

How Apache Struts Vulnerabilities Enable Remote Code Execution works

The Apache Struts project fixed four vulnerabilities (S2-075 to S2-078) in Struts 7.4.0 and 6.12.0 on 2026-10-02: an OGNL injection in the legacy RESTful action mapper that can lead to remote code execution, a BigDecimal rendering denial of service, an unbounded request body read in the REST plugin, and a shared message formatter that can leak date/time values between concurrent users. No active exploitation or public PoC is reported.

On 2026-10-02 the Apache Struts project released Struts 7.4.0 and 6.12.0 (both General Availability) and published four security bulletins, S2-075 through S2-078. Cyber Security News covered the disclosure on 2026-10-06. The release announcement strongly advises all developers to upgrade. Struts 7.3.0 and 6.11.0, released 2026-08-01, are the last vulnerable releases in their lines.

CVE-2026-104711 (S2-075, rated Moderate by Apache, reporter LeaveSong) is an OGNL injection in the legacy RESTful action mapper. A crafted request can inject an OGNL expression that may lead to remote code execution. Affected versions are Struts 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. The S2-075 bulletin attaches the condition that the OGNL allowlist is disabled to the 7.x range; the press article states the allowlist-disabled condition more broadly. Applications using the default mapper, the restful2 mapper or the Struts REST plugin are not affected. The only workaround is to switch away from the legacy RESTful action mapper.

CVE-2026-104712 (S2-076, Moderate, reporter 0xCc.zhang) is a resource-exhaustion denial of service. When request parameters bind to java.math.BigDecimal properties and are rendered through Struts tag libraries, small requests can produce responses many orders of magnitude larger. Affected versions are 2.5.14-2.5.33 (EOL), 6.0.0-6.11.0 and 7.0.0-7.3.0. Applications that do not bind BigDecimal properties, that use JSON/REST plugin responses, or that use other numeric types are unaffected. The workaround is a custom BigDecimal type converter registered in struts-conversion.properties (xwork-conversion.properties on 2.5.x) that bounds the scale before rendering.

CVE-2026-104713 (S2-077, Important, reporter n0mi1k) is a memory-exhaustion denial of service. The REST plugin reads a request body into memory with no bound, so oversized requests can exhaust the heap. Affected versions are 2.1.8-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. Struts has no configuration-only fix. The patched releases add a default limit of 2,097,152 characters (2 MB), configurable with struts.rest.content.maxLength. Until upgraded, defenders should enforce a maximum request body size in the reverse proxy or servlet container.

CVE-2026-104714 (S2-078, Moderate, reporter n0mi1k) is a concurrency flaw. A message formatter is shared between concurrently served requests. When localized messages format date or time arguments, one user's value can appear in another user's response, or rendering can fail and surface as a server error. Ordinary concurrent traffic triggers it, with no malicious input needed. Affected versions are 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. The workaround is to format date/time values before message interpolation.

The sources state no numeric CVSS score, no active exploitation, no public PoC and no network or file indicators of compromise. Apache's own ratings are Moderate (104711, 104712, 104714) and Important (104713). The HIGH severity assigned here is an analyst estimate based on the remote code execution class of CVE-2026-104711, not a source-stated score. The CVE ids themselves come from the Apache bulletins; NVD and web searches returned nothing for them at the time of research.

MITRE ATT&CK techniques used in TL-2026-2982

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.003 Application Exhaustion Flood; T1499.004 Application or System Exploitation

Affected products and versions in Apache Struts Vulnerabilities Enable Remote Code Execution

  • Apache Software Foundation — Apache Struts (legacy RESTful action mapper) - CVE-2026-104711
    Vulnerable versions: 2.0.0-2.3.37; 2.5.0-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0 (with OGNL allowlist disabled)
    Fixed in: 6.12.0; 7.4.0
  • Apache Software Foundation — Apache Struts (BigDecimal rendering via tag libraries) - CVE-2026-104712
    Vulnerable versions: 2.5.14-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0
    Fixed in: 6.12.0; 7.4.0
  • Apache Software Foundation — Apache Struts REST plugin - CVE-2026-104713
    Vulnerable versions: 2.1.8-2.3.37; 2.5.0-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0
    Fixed in: 6.12.0; 7.4.0
  • Apache Software Foundation — Apache Struts (shared message formatter) - CVE-2026-104714
    Vulnerable versions: 2.0.0-2.3.37; 2.5.0-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0
    Fixed in: 6.12.0; 7.4.0

Remediation for Apache Struts Vulnerabilities Enable Remote Code Execution

Patches

  • Upgrade to Apache Struts 7.4.0 or later (requires Java 17 and JakartaEE)
  • Upgrade to Apache Struts 6.12.0 or later on the 6.x maintenance line (Servlet API 3.1, JSP API 2.1, Java 8)

Immediate actions

  • Inventory applications built on Apache Struts, including transitive and embedded copies, and identify any that use the legacy RESTful action mapper or the REST plugin
  • Enforce a maximum request body size in the reverse proxy or servlet container in front of any endpoint that accepts request bodies (mitigates CVE-2026-104713)
  • Confirm the OGNL allowlist is enabled on Struts 7.x deployments

Workarounds

  • CVE-2026-104711: use the default action mapper, the restful2 mapper or the Struts REST plugin instead of the legacy RESTful action mapper
  • CVE-2026-104712: register a custom java.math.BigDecimal converter that bounds scale, in struts-conversion.properties (xwork-conversion.properties on 2.5.x)
  • CVE-2026-104713: enforce a request body limit at the reverse proxy or servlet container; patched versions default to 2,097,152 characters, configurable via struts.rest.content.maxLength
  • CVE-2026-104714: format date/time values before passing them to localized messages and interpolate the already-formatted value

Longer-term hardening

  • Migrate off the legacy RESTful action mapper to the default mapper, the restful2 mapper or the Struts REST plugin
  • Move off end-of-life Struts 2.3.x and 2.5.x lines, which will not receive these fixes
  • Subscribe to Apache Struts security bulletins and track the Struts release feed

CVEs associated with Apache Struts Vulnerabilities Enable Remote Code Execution

CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714

Timeline of Apache Struts Vulnerabilities Enable Remote Code Execution

  • Apache Struts 7.3.0 and 6.11.0 are released; they are the latest releases affected by CVE-2026-104711 to CVE-2026-104714.
  • Bulletins S2-077 (CVE-2026-104713, unbounded REST plugin request body read) and S2-078 (CVE-2026-104714, shared message formatter exposes date/time values across concurrent requests) published; both reported by n0mi1k.
  • Bulletin S2-076 published for CVE-2026-104712, a denial of service from disproportionately large responses when rendering BigDecimal request parameters (reporter: 0xCc.zhang).
  • Bulletin S2-075 published for CVE-2026-104711, an OGNL injection in the legacy RESTful action mapper that may lead to remote code execution (reporter: LeaveSong).
  • Apache Struts 7.4.0 and 6.12.0 are released as General Availability, fixing four vulnerabilities, with the announcement strongly advising all developers to upgrade.
  • Cyber Security News reports the four Struts vulnerabilities and states no active exploitation has been reported.

Sources cited for Apache Struts Vulnerabilities Enable Remote Code Execution

Detection coverage for TL-2026-2982

As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2982 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats