Apache Struts

Apache Software Foundation · current 7.4.0

Are you Apache Software Foundation? Claim this page

The current version of Apache Struts is 7.4.0 (as of 17/09/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2017-5638Apache Struts Remote Code Execution VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2020-17530Apache Struts Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2012-0391Apache Struts 2 Improper Input Validation Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 21 Jul 22

  • CVE-2017-9791Apache Struts 1 Improper Input Validation Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 10 Aug 22

  • CVE-2013-2251Apache Struts Improper Input Validation Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2016-3081Apache Struts Command Injection Vulnerability

    8.1 high · over the network, without login · CISA deadline: 1 day left

  • CVE-2018-11776Apache Struts Remote Code Execution Vulnerability

    8.1 high · over the network, without login · CISA deadline was 3 May 22

  • CVE-2017-9805Apache Struts Deserialization of Untrusted Data Vulnerability

    8.1 high · over the network, without login · CISA deadline was 3 May 22

  • CVE-2006-1547Apache Struts 1 ActionForm Denial-of-Service Vulnerability

    7.5 high · over the network, without login · CISA deadline was 21 Jul 22

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Support cycles (endoflife.date)

CycleLatest versionStatus
77.4.0supported
66.12.0supported
2.52.5.33End of Life
2.32.3.37End of Life
2.22.2.3.1End of Life
2.12.1.8.1End of Life
2.02.0.14End of Life
1.31.3.10End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
7.4.0STABLE17/09/2026–
7.3.0STABLE01/08/2026–

Frequently asked questions

What is the latest version of Apache Struts?
Apache Struts 7.4.0, released 17/09/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Apache Struts release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Apache Struts updates?
Tick Apache Struts off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Apache Struts version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Apache Struts version and keeps it up to date. Anyone may embed it, no account needed.

Apache Struts badge
[![Apache Struts](https://patchletter.com/badge/apache-struts.svg)](https://patchletter.com/en/software/apache-struts)
https://patchletter.com/badge/apache-struts.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Servers & Databases