ZeroDayAlert

CVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Apache Struts Added to KEV 2026-10-08 Federal due 2026-10-11 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Apache Struts applications where Dynamic Method Invocation (DMI) is enabled are vulnerable to remote command injection. The vulnerability allows attackers to execute arbitrary code on the server. The record does not specify which Struts versions are affected, so you must establish your inventory scope and version baseline independently.

How to check whether this touches you

  • Search your asset inventory for Apache Struts deployments; note the application names and teams responsible.
  • Determine whether Dynamic Method Invocation is enabled in each Struts configuration (check struts.enable.DynamicMethodInvocation setting and related security filters).
  • Establish network reachability: whether each instance accepts HTTP/HTTPS requests from outside your perimeter, or only from trusted internal sources.
  • Obtain the running version number from application logs, administrative consoles, or version endpoints; cross-reference against vendor patch announcements to identify whether your version includes a fix.

What to do

  1. If you cannot patch immediately, disable Dynamic Method Invocation in your Struts configuration (set struts.enable.DynamicMethodInvocation = false) to eliminate the attack surface.
  2. Reduce reachability by placing Struts applications behind a web application firewall or reverse proxy that filters suspicious method parameters; restrict network access to authorised users and systems only.
  3. Enable and retain HTTP request logging with focus on parameters passed to action methods; log both successful and rejected requests.
  4. Treat internet-facing Struts instances as high priority for patching under BOD 26-04 timelines. Consult vendor instructions for the applicable patch or upgrade path for your version.
  5. If patching is not feasible and you cannot mitigate through configuration or network controls, escalate to your change advisory board and security leadership for risk acceptance or discontinuation of the service.

If you find you were exposed

Search your HTTP access logs and application logs backwards from the disclosure date for suspicious method: parameters or unusual action invocations that might indicate exploitation attempts. Log retention is your main constraint; if logs have been rotated, you may only be able to confirm exposure through file integrity monitoring or endpoint detection tools if they retained forensic data. If you find evidence of exploitation, treat it as confirmed compromise and initiate incident response procedures, including credential review and lateral movement investigation.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2016-3081 is being exploited. It cannot tell you whether Struts is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →