Apache Struts
Apache Software Foundation · current 7.3.0
The current version of Apache Struts is 7.3.0 (as of 01/08/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
9.8 critical · over the network, without login · CISA deadline was 3 May 22
- CVE-2020-17530Apache Struts Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 3 May 22
- CVE-2012-0391Apache Struts 2 Improper Input Validation Vulnerability
9.8 critical · over the network, without login · CISA deadline was 21 Jul 22
- CVE-2017-9791Apache Struts 1 Improper Input Validation Vulnerability
9.8 critical · over the network, without login · CISA deadline was 10 Aug 22
- CVE-2013-2251Apache Struts Improper Input Validation Vulnerability
9.8 critical · over the network, without login · CISA deadline was 15 Apr 22
- CVE-2018-11776Apache Struts Remote Code Execution Vulnerability
8.1 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2017-9805Apache Struts Deserialization of Untrusted Data Vulnerability
8.1 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2006-1547Apache Struts 1 ActionForm Denial-of-Service Vulnerability
7.5 high · over the network, without login · CISA deadline was 21 Jul 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Apache Struts: Mehrere Schwachstellen
WID-SEC-W-2026-2848 · 17 Aug
- Apache log4j: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2022-0351 · 8 Jul
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 7 | 7.3.0 | supported |
| 6 | 6.11.0 | supported |
| 2.5 | 2.5.33 | End of Life |
| 2.3 | 2.3.37 | End of Life |
| 2.2 | 2.2.3.1 | End of Life |
| 2.1 | 2.1.8.1 | End of Life |
| 2.0 | 2.0.14 | End of Life |
| 1.3 | 1.3.10 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 7.3.0 | STABLE | 01/08/2026 | – |
Frequently asked questions
- What is the latest version of Apache Struts?
- Apache Struts 7.3.0, released 01/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Apache Struts release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Apache Struts updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Apache Struts update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Apache StrutsEmbed this badge
Shows the current Apache Struts version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/apache-struts)https://patchletter.com/badge/apache-struts.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).