S4E just found a high top 10 tcp port service scan
high·Product Based Network Vulnerabilities·Updated Jul 31, 2026

CVE-2025-68493 Scanner

CVE-2025-68493 Scanner - XML External Entity (XXE) vulnerability in Apache Struts XWork

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-68493
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Apache Strutsby Apache Software Foundation
AFFECTED< 2.2.1SAFE ✓≥ 2.2.1
Apache Strutsby Apache Software Foundation
2.2.1
Red Hat Enterprise Linux 8by Red Hat
Red Hat Fuse 7by Red Hat
Updated Aug 22, 2026View on NVD →
Detail

Apache Struts XWork is predominantly used in enterprise applications as a part of the Apache Struts framework for developing Java EE web applications. It is adopted by developers and organizations due to its capabilities in handling complex web application structures effectively and its integrations with other Java frameworks. The utilization of Struts XWork extends across various industries for creating dynamic, content-rich, and data-driven web applications. Many software development companies incorporate it into their projects for enhanced MVC architecture, leading to seamless project management and execution. It is known for its robustness in building high-performance web applications that require scalable, reusable, and portable solutions. XWork essentially allows developers to create secure and efficient environments for their web-based services while leveraging the strengths of the Struts framework.

The vulnerability known as XML External Entity (XXE) occurs when an application processes XML input incorrectly, allowing the inclusion of an external entity. Attackers can exploit this flaw to tamper with the application's execution, potentially leading to the exposure of sensitive information or causing a system malfunction. The particular vulnerability in Apache Struts XWork versions involves inadequate validation in XML processing. By exploiting this flaw, malicious users can read local files or even facilitate denial-of-service attacks on affected systems. The existence of such an exploit showcases the inherent risks posed by frameworks that process XML data without stringent verification checks. XXE can be particularly harmful since it combines the potential for both data breach and service disruption in an affected application.

In Apache Struts XWork, the XXE vulnerability is identified within the XML parsing mechanism that improperly handles external entity declarations. Specifically, this occurs due to missing validation checks on XML input sent to endpoint "/struts2-xml-parser/xmlParserNoDtdParse." This endpoint is susceptible to crafted XML payloads that include malicious entities capable of bypassing the system's secured data zones. Attackers target the Content-Type of "application/x-www-form-urlencoded" in HTTP POST requests to execute unauthorized read requests from internal files. By introducing external references in these XML files, malicious entities are able to manipulate the system's logic, resulting in unauthorized disclosures or service failures. This vulnerability highlights significant risk factors within XML parsing logic, particularly when coupled with lax or absent validation strategies.

If the XML External Entity (XXE) vulnerability in Apache Struts XWork is exploited, it can have severe repercussions on the affected system. An attacker harnessing this flaw could potentially access sensitive configuration files and internal data not intended for public consumption, which can lead to compromising system security and user data. Besides unauthorized information access, exploitation may result in service interruptions, thus disrupting the availability of web applications relying on XWork. Moreover, such vulnerabilities provide an entry point for further malicious activities, potentially opening up the affected environment for broader attacks. The ramifications might extend beyond immediate data loss or service disruption, implicating customer trust and regulatory compliance for organizations relying on susceptible software. Importantly, the existence of this vulnerability underscores the essential requirement for regular security audits and timely updates in software handling XML data.

REFERENCES

Solution Advice
  • Immediately upgrade Apache Struts XWork to version 6.1.1 or newer to ensure the vulnerability is patched.
  • Review and audit configurations to ensure XML parsers disallow external entity definitions to mitigate future XXE threats.
  • Implement strict input validation on XML data to prevent potential injection of malicious entities.
  • Utilize Web Application Firewalls (WAF) to detect and block anomalous XML requests targeting known vulnerable endpoints.
  • Regularly update software environments and apply security patches from trusted vendors as part of effective software maintenance protocols.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-68493 Scanner - XML External Entity (XXE) vulnerability in Apache Struts XWork S4E