← Blog · · df00tech

CISA Adds 2016 Apache Struts Command Injection Flaw (CVE-2016-3081) to KEV

breaking kev Apache CVE-2016-3081

What happened

CISA has added CVE-2016-3081, a command injection vulnerability in Apache Struts (tracked by the project as S2-032), to its Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild exploitation. According to Apache's advisory, the flaw allows remote attackers to execute arbitrary code via the method: prefix parameter when Dynamic Method Invocation (DMI) is enabled. CVSS scoring for this entry is not provided in the KEV data, and ransomware use is currently listed as unknown.

Why it matters

This is a roughly decade-old Struts vulnerability, which makes its appearance in KEV notable — it points to attackers continuing to find and exploit legacy, unpatched Struts deployments rather than a newly disclosed flaw. Struts has historically been embedded in enterprise Java web applications, so organizations running older or unmaintained Struts-based apps — including ones inherited through acquisitions or third-party vendors — are at risk. Successful exploitation can lead to full remote code execution on the affected server.

Who's affected

  • Organizations running Apache Struts versions vulnerable to S2-032 with Dynamic Method Invocation enabled
  • Any internet-facing Struts application, especially those not actively maintained or inventoried

What defenders should do now

  • Inventory all Java web applications for Apache Struts usage, including vendor/third-party software that may bundle it
  • Confirm whether Dynamic Method Invocation is enabled and disable it if not required, per Apache's guidance
  • Patch to a Struts version that addresses S2-032 if not already done
  • Hunt web server/application logs for requests containing a method: prefix parameter combined with suspicious OGNL-style expressions or shell command patterns
  • Watch for anomalous child processes spawned by Java/Struts application server processes (e.g., java.exe/catalina spawning cmd, sh, or bash)
  • Treat any federal or high-value Struts-facing asset as a priority per CISA KEV remediation timelines

Developing intel

This KEV addition is fresh as of 2026-10-08 and details beyond Apache's original advisory — such as specific threat actors, campaigns, or ransomware linkage — are not yet confirmed. We will update this post as more information becomes available. For the original vulnerability advisory, see Apache's S2-032 advisory.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.