Apache Struts Command Injection Vulnerability (CVE-2016-3081) is being actively exploited, CISA warns
CISA added CVE-2016-3081 (Apache Struts) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
Excerpt from the primary source: CISA Known Exploited Vulnerabilities
Who is affected
Security professionals
Affected technology: Struts
Why it matters
CISA lists this as exploited in the wild. Unpatched Struts systems are exposed to active attacks now.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Patch
Apply the vendor's security update for Struts. Check the linked advisory for affected and fixed versions, and put internet-facing systems first.
CISA's required action for CVE-2016-3081: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines." US federal civilian agencies must comply by October 11, 2026.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Related
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.
Treat this as an emergency.
International coalition seizes tools used by cyber firm behind Flax Typhoon
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.
Making sure the checks get printed
Pierre's debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn't an option.
Cisco Patches a Dozen Critical Vulnerabilities
The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.
Apply the vendor's security update for Cisco networking & security.
