← back
CVE-2016-3081observed exploitation

CVE-2016-3081

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 93%
from disclosure to weapon6 days
Published on NVDApr 26
1st PoC+6d
metasploit+1d
VulnCheck+3740d
exploitation probability
93%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.