BoletimSec•October 7, 2026•🇵🇹Translated from Portuguese

Apache Struts CVE-2026-104711 Enables Remote Code Execution via Legacy RESTful Mapper

Apache Struts has released fixes for four vulnerabilities, including one that allows unauthenticated remote code execution when the legacy RESTful mapper is enabled.

The flaw, identified as CVE-2026-104711, is an OGNL injection that depends on the application using the deprecated RESTful mapper. Applications running the default mapper, restful2, or the official Struts REST plugin are not affected. In version 7.x the issue only manifests when the OGNL allow-list is disabled.

When the legacy mapper is active, it extracts action names and parameters straight from the URL. Attackers can therefore supply a malicious OGNL expression that is evaluated by the framework, leading to arbitrary code execution.

Affected versions include 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Patches are available in 6.12.0 and 7.4.0 and later releases.

The three additional vulnerabilities do not result in code execution. Two affect availability: one causes small requests to generate disproportionately large responses, consuming CPU and bandwidth, while the other exhausts memory by accepting unbounded request bodies. The memory-exhaustion issue received an “important” severity rating and now enforces a default limit of 2,097,152 characters.

The fourth flaw is subtler and does not require malicious input. Shared message formatters can interfere between concurrent requests, potentially leaking data or producing rendering errors under normal traffic.

Related articles

BoletimSec•Vulnerabilities & Exploits

Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence

Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.

Habr•Vulnerabilities & Exploits

Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery

The article explores how automated penetration testing and Breach and Attack Simulation tools have evolved to provide continuous validation of security controls beyond annual manual pentests. It explains the distinction between BAS, which tests individual attack techniques against security tools using frameworks like MITRE ATT&CK, and autopentest solutions that build complete attack paths to critical assets. Russian vendor Positive Technologies released PT Dephaze 3.0 in October 2025, incorporating machine learning for controlled internal pentesting and earning the National Runet Award. Globally, AI-driven systems demonstrated superior performance, with XBOW topping HackerOne rankings by discovering over 1,000 vulnerabilities including 54 critical ones in just 90 days. Google’s Big Sleep project, combining DeepMind and Project Zero, identified and helped patch CVE-2025-6965 in SQLite before widespread exploitation. These developments underscore the need to integrate automated validation into vulnerability management processes under the emerging CTEM framework.

Security NEXT•Vulnerabilities & Exploits

Critical SSRF Vulnerability Affects SonicWall SMA1000 Series Remote Access Appliances

SonicWall has disclosed four vulnerabilities in its SMA1000 series remote access products, with one rated critical. The most severe issue, CVE-2026-102255, is a server-side request forgery flaw in the WorkPlace interface that allows unauthenticated attackers to abuse the appliance as a forward proxy and reach internal functions. The vulnerability received the maximum CVSSv3.0 base score of 10.0. Two additional flaws, CVE-2026-102256 and CVE-2026-102257, enable authenticated OS command injection and unauthenticated path traversal via crafted archives, respectively. No exploitation has been observed in the wild at the time of disclosure. SonicWall has released updates to address all issues.

Security NEXT•Vulnerabilities & Exploits

WordPress 7.1.3 Security Release Fixes Seven Vulnerabilities Including Stored XSS and SQL Injection

The WordPress development team has released version 7.1.3 as a maintenance and security update addressing multiple vulnerabilities. The release includes seven security fixes and four additional bug corrections. Among the security issues resolved is a stored cross-site scripting flaw that allowed pending comments to execute scripts in the administrative interface. Other fixes cover a denial-of-service condition in URL handling, an SQL injection vulnerability in the WXR export feature, and unauthorized disclosure of comments attached to private or unpublished posts. Additional patches address an XSS issue in the Imgur embed functionality, improper sticky post permissions for users with the Author role, and a parameter manipulation problem affecting hook action names.