Attackers are actively scanning for and attempting to exploit critical Apache Struts file upload vulnerabilities CVE-2024-53677 and CVE-2023-50164, both of which stem from improper handling of upload parameters that can enable path traversal and unauthorized file placement. Security researchers reported internet-wide enumeration and exploitation activity following public disclosure and the appearance of proof-of-concept code on GitHub and in technical write-ups, with attackers seeking to upload malicious files into restricted directories.
Successful exploitation can allow deployment of JSP web shells and lead to remote code execution on vulnerable Struts applications, depending on how file upload features are exposed and sanitized in each environment. The flaws affect multiple Struts branches, including legacy 2.x and 6.x releases, and defenders have been urged to upgrade to fixed versions such as Struts 2.5.33, 6.3.0.2, or 6.4.0 as applicable, migrate away from legacy upload mechanisms, restrict access to upload interfaces, apply WAF protections, and monitor for suspicious JSP file creation and execution.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2024-53677, a critical Struts2 path traversal flaw in file upload logic. The vulnerability could permit unauthorized file uploads to restricted directories and potentially lead to remote code execution.
Cisco announced that it was investigating whether its products were exposed to CVE-2023-50164. The statement reflected vendor response activity following disclosure and PoC release.
The first public proof-of-concept exploits for CVE-2023-50164 were released. Their publication lowered the barrier for attackers to test and weaponize the Struts vulnerability.
The first public technical write-up for CVE-2023-50164 was published, revealing exploitation details for the Struts file upload flaw. This increased public understanding of how the bug could be abused.
Apache released an update addressing CVE-2023-50164 in Struts. The fix covered a critical remote code execution issue affecting multiple Struts branches.
Researcher Steven Seeley of Source Incite reported the Apache Struts vulnerability CVE-2023-50164. The flaw involved path traversal in file upload handling that could enable arbitrary file write and remote code execution.
The advisory reported ongoing large-scale scanning for CVE-2023-50164 and distinct attempts to deploy web shells through the flaw. These observations showed attackers moving from public research to active exploitation activity.
Public proof-of-concept code for CVE-2024-53677 was observed on GitHub, while SANS and mnemonic reported enumeration and exploitation attempts targeting vulnerable Struts systems. mnemonic said it had first-hand visibility into broad exploitation attempts against its customer base.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
mnemonic.io
Open sourcemnemonic.io
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.