Product
low
advisory
Denial of Service Vulnerability in Apache Struts JSON Plugin (CVE-2026-73633)
1 TTP 1 CVEA public proof-of-concept exploit for CVE-2026-73633 allows unauthenticated attackers to perform denial-of-service attacks by forcing excessive CPU and memory consumption via the Apache Struts JSON plugin.
Struts 2
1t
1c
high
advisory
Apache Struts CVE-2023-50164 Exploitation Leading to Web Shell Deployment
2 rules 3 TTPs 1 CVEExploitation of CVE-2023-50164, a critical path traversal vulnerability in Apache Struts 2, is detected by identifying malicious multipart/form-data POST requests with WebKitFormBoundary targeting Struts .action upload endpoints, followed by JSP web shell creation in Tomcat's webapps directories, indicating remote code execution.
Struts 2
apache-struts
webshell
cve-2023-50164
initial-access
persistence
command-and-control
2r
3t
1c