Apache Struts developers released fixes for CVE-2024-53677, a critical vulnerability in the framework's file upload handling that can allow malicious file upload and remote code execution in applications using FileUploadInterceptor. The flaw affects Struts versions 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.3.0.2, and has been assigned a CVSS 4.0 score of 9.5. Public proof-of-concept exploit code is available, and CSIRT.SK reported that the vulnerability is being actively exploited in the wild.
Apache's guidance points organizations to Struts 6.4.0 or later, but the vendor's file upload documentation indicates remediation is not limited to patching alone: affected applications must also update source code to adopt the framework's newer file upload mechanism. Defenders are advised to review network and security logs for signs of compromise, as exposed internet-facing Struts applications that still rely on the legacy upload interceptor face elevated risk of exploitation.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2024-53677 was being actively exploited in the wild. The notice said the flaw could be abused for malicious file upload and remote code execution in applications using FileUploadInterceptor, and that public proof-of-concept exploit code was available.
Apache Struts developers released security updates to address CVE-2024-53677, a critical file upload vulnerability affecting multiple Struts version ranges. Apache recommended upgrading to Struts 6.4.0 or later and noted that remediation also requires application source code changes to use the new file upload mechanism.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.