← Back to list

CRITICAL ALERT: Apache Struts2 XXE Exposed (CVE-2025–68493)

ZAST.AI discovered a high severity XXE vulnerability in XWork-Core allows threat actors steal files & trigger SSRF.

ZAST AI · 2026-01-13 13:02 · 0 claps · 0.6 min read
#appsec #cybersecurity #xxe #cve
Open on Medium ↗
Wiki topics: 🌐 · Web Development 🔒 · Cybersecurity

CRITICAL ALERT: Apache Struts2 XXE Exposed (CVE-2025–68493)

ZAST.AI discovered a high severity XXE vulnerability in XWork-Core allows threat actors steal files & trigger SSRF.

The flaw was hidden in DomHelper’s unconfigured SAX parser.

⚡ Discovered by ZAST.ai AI Agent — proving once again that AI-driven logic beats pattern matching.

Patch immediately (Struts2 <= 6.0.3)!

🔗 Vulnerability reports: https://cwiki.apache.org/confluence/display/WW/S2-069


메타데이터
post_id
aba57becc5e6
slug
critical-alert-apache-struts2-xxe-exposed-cve-2025-68493-aba57becc5e6
url
https://medium.com/@zastxai/critical-alert-apache-struts2-xxe-exposed-cve-2025-68493-aba57becc5e6
canonical_url
https://medium.com/@zastxai/critical-alert-apache-struts2-xxe-exposed-cve-2025-68493-aba57becc5e6
author_url
https://medium.com/@zastxai
status
ok
fetched_at
2026-06-25 07:00:49