Cyber & AI intelligence
Wasteland.
Briefs indexed3090
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2016-3081 2026-10-08

CISA Adds Apache Struts Command Injection Flaw CVE-2016-3081 to KEV

"CISA has added CVE-2016-3081 to its Known Exploited Vulnerabilities (KEV) catalog. The Apache Struts command injection flaw allows remote code execution when Dynamic Method Invocation is enabled, and CISA has confirmed…"

CISA has added CVE-2016-3081 to its Known Exploited Vulnerabilities (KEV) catalog. The Apache Struts command injection flaw allows remote code execution when Dynamic Method Invocation is enabled, and CISA has confirmed it is being actively exploited.

What Is It

CVE-2016-3081 is a command injection vulnerability (CWE-77) in Apache Struts. When Dynamic Method Invocation (DMI) is enabled, a remote attacker can run arbitrary code through the method: prefix. NVD links the issue to chained expressions. Apache tracks it as security bulletin S2-032.

NVD scores it 8.1 (HIGH) under CVSS v3.x with vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The legacy CVSS v2 score is 9.3. An attacker needs no privileges and no user interaction, but attack complexity is rated High.

Why It Matters

What's Vulnerable

According to NVD's description, these Apache Struts versions are affected when Dynamic Method Invocation is enabled:

NVD's CPE configuration also lists earlier Struts 2.x releases, starting at 2.0.0, as vulnerable. Check any Struts 2 deployment, including products that embed Struts, and confirm whether DMI is enabled.

Patch Status

CISA's required action is to apply mitigations according to vendor instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance. If mitigations are not available, stop using the product. Organizations must also assess each asset's internet exposure.

Apache's S2-032 advisory is the vendor reference for remediation. Oracle's July 2016 and October 2016 Critical Patch Updates also address the flaw in affected Oracle products.

Sources