What is CVE-2016-3081?
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
Timeline
- 2016-04-26Published to the U.S. National Vulnerability Database (NVD)
- 2026-10-08Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-10-09NVD record last updated
- 2026-10-11CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Apache Struts Command Injection Vulnerability
Affected product
Apache Struts
NVD also lists CPE entries for: Apache Struts, Oracle Siebel E-Billing
Remediation Steps
- Apply the vendor security update for Apache Struts as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of October 2026 (October 5 – 11)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.