CVE-2016-3081

Apache Struts Command Injection Vulnerability

8.1
CVSS 3.1
93.4 %
EPSS (current)
2026-10-08
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Apache / Struts

Published: 2016-04-26 · Due (CISA): 2026-10-11

CWE: CWE-77 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2016/CVE-2016-3081.yamlApache S2-032 Struts - Remote Code Execution–
metasploitexploit/multi/http/struts_dmi_execexploit/multi/http/struts_dmi_exec2016-04-27
exploitdb39756Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)2016-05-02

References only — no downloads or instructions.

Sources