
Key points
- CISA added CVE-2016-3081 to the KEV catalog on 8 October 2026.
- Federal agencies have until 11 October 2026 to apply mitigations or discontinue use.
- The vulnerability allows remote code execution via Dynamic Method Invocation.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2016-3081 to its Known Exploited Vulnerabilities (KEV) catalog. This action imposes a strict deadline for federal civil executive branch agencies to mitigate the risk or discontinue the affected product by 11 October 2026.
The entry, published on 8 October 2026, classifies the issue as an Apache Struts command injection vulnerability. According to CISA guidance, agencies must apply mitigations in accordance with vendor instructions. If mitigations are unavailable, organisations must discontinue use of the product. Stakeholders are also required to evaluate each asset’s internet exposure and ensure adherence to CISA’s Binding Operational Directive 26-04, which prioritises security updates based on risk.
Context and background
The vulnerability affects Apache Struts versions 2.3.19 through 2.3.20.2, 2.3.21 through 2.3.24.1, and 2.3.25 through 2.3.28. The flaw exists when Dynamic Method Invocation is enabled. Remote attackers can exploit this configuration to execute arbitrary code via the method: prefix, often involving chained expressions.
The National Vulnerability Database assigns the vulnerability a CVSS score of 8.1, rating it as high severity. The weakness is associated with CWE-77, which relates to improper neutralisation of special elements used in an OS command.
Who is affected
Organisations running the specified versions of Apache Struts with Dynamic Method Invocation enabled are at risk. Federal agencies are the primary entities subject to the immediate compliance deadline. However, any entity using the affected software versions faces potential remote code execution if the insecure configuration remains active.
What happens next
Federal agencies must review their assets to determine if they are running vulnerable versions of Apache Struts. Those with internet-exposed assets must prioritise mitigation efforts to meet the 11 October deadline. CISA has linked this requirement to its Forensics Triage Requirements, indicating the seriousness of the threat.
What to do and how to stay safe: Apache Struts
- Inventory all servers and applications to identify instances of Apache Struts versions 2.3.19 to 2.3.28.
- Check configuration files to determine if Dynamic Method Invocation is enabled on any identified instances.
- Disable Dynamic Method Invocation if it is not strictly required for application functionality.
- Monitor for vendor updates or patches that address the command injection flaw once the vendor provides an update.
Step-by-step guide: Vulnerability Scanning for Small Teams: Practical Steps and Limits
General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Which Apache Struts versions are affected by CVE-2016-3081?
Versions 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28 are affected when Dynamic Method Invocation is enabled.
What is the deadline for federal agencies to mitigate this vulnerability?
Federal agencies must mitigate the risk or discontinue use by 11 October 2026.
How severe is this vulnerability rated?
The National Vulnerability Database rates CVE-2016-3081 as high severity with a CVSS score of 8.1.



