Apache Struts Command Injection Vulnerability (CVE-2016-3081) is being actively exploited, CISA warns
CISA lists this as exploited in the wild. Unpatched Struts systems are exposed to active attacks now.
Apply the vendor's security update for Struts.
