CISA has added CVE-2016-3081 to its Known Exploited Vulnerabilities (KEV) catalog. The Apache Struts command injection flaw allows remote code execution when Dynamic Method Invocation is enabled, and CISA has confirmed it is being actively exploited.
What Is It
CVE-2016-3081 is a command injection vulnerability (CWE-77) in Apache Struts. When Dynamic Method Invocation (DMI) is enabled, a remote attacker can run arbitrary code through the method: prefix. NVD links the issue to chained expressions. Apache tracks it as security bulletin S2-032.
NVD scores it 8.1 (HIGH) under CVSS v3.x with vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The legacy CVSS v2 score is 9.3. An attacker needs no privileges and no user interaction, but attack complexity is rated High.
Why It Matters
- Active exploitation confirmed: CISA added CVE-2016-3081 to KEV on 2026-10-08. CISA's SSVC assessment lists exploitation as "active" and technical impact as "total."
- Short deadline: Federal agencies must act by 2026-10-11, three days after the KEV listing.
- Forensic triage required: KEV marks this entry "Forensics Triage: Yes," so CISA's Forensics Triage Requirements apply in addition to patching.
- Public exploit material: NVD references include Rapid7 Metasploit modules (
struts_dmi_exec), an Exploit-DB entry and a Packet Storm write-up. - Ransomware use: KEV lists known ransomware campaign use as "Unknown."
- Wide reach: CISA notes the flaw may affect open-source components, third-party libraries or proprietary implementations used across different products. NVD also references Oracle and Huawei security advisories.
What's Vulnerable
According to NVD's description, these Apache Struts versions are affected when Dynamic Method Invocation is enabled:
- 2.3.19 through 2.3.20.2
- 2.3.21 through 2.3.24.1
- 2.3.25 through 2.3.28
NVD's CPE configuration also lists earlier Struts 2.x releases, starting at 2.0.0, as vulnerable. Check any Struts 2 deployment, including products that embed Struts, and confirm whether DMI is enabled.
Patch Status
CISA's required action is to apply mitigations according to vendor instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance. If mitigations are not available, stop using the product. Organizations must also assess each asset's internet exposure.
Apache's S2-032 advisory is the vendor reference for remediation. Oracle's July 2016 and October 2016 Critical Patch Updates also address the flaw in affected Oracle products.
Sources
- CISA KEV Catalog – CVE-2016-3081
- NVD – CVE-2016-3081
- Apache Struts Security Bulletin S2-032
- Apache Confluence – S2-032
- CISA BOD 26-04
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements
- Oracle CPU July 2016
- Oracle CPU October 2016
- Huawei Security Advisory
- Rapid7 – struts_dmi_exec module
- Exploit-DB 39756