# CERT-FR Warns of Apache Struts Flaws

Published: 2026-10-09 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/123d9eb3-4f9e-5981-b68d-23114b9e78e9/cert-fr-warns-of-apache-struts-flaws

> CERT-FR advisory details four new Apache Struts vulnerabilities enabling remote code execution, denial of service, and data exposure; patches available.

CERT-FR has published an advisory covering four vulnerabilities in Apache Struts, affecting Struts 2 (no longer maintained), Struts 6.x before 6.12.0, and Struts 7.x before 7.4.0. The flaws, tracked as CVE-2026-104711 through CVE-2026-104714 and documented in Apache's own S2-075 through S2-078 bulletins (published 2 October 2026), can allow remote code execution, remote denial of service, and unauthorized disclosure of confidential data.

No in-the-wild exploitation is mentioned in this advisory. Defenders running affected Struts versions should consult the linked Apache security bulletins for patch details and upgrade to Struts 6.12.0, 7.4.0, or later as applicable. Organizations still running the unsupported Struts 2 line should prioritize migration, as no fixes will be issued for that branch.

## Mentioned in this report

- Vulnerabilities: CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1290

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/123d9eb3-4f9e-5981-b68d-23114b9e78e9/cert-fr-warns-of-apache-struts-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
