CrowdSecLive Exploit Tracker
Background NoiseCVE-2018-11776Public Exploit

Apache Struts - RCE (CVE-2018-11776)

PublishedAug 22, 2018
First SeenJun 25, 2026
Last Seen
Reported
CVSS8.1
javaweb_application

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

psychologyCrowdSec Analysis

CVE-2018-11776 is a remote code execution vulnerability in Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16, which can be exploited when certain namespace configurations are present. Attackers can leverage this flaw to execute arbitrary code on affected servers without authentication, potentially leading to full system compromise. This vulnerability is particularly dangerous for web applications using the Convention Plugin or misconfigured namespaces, making it a prime target for remote attacks.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network data shows that most actors exploiting CVE-2018-11776 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2018-11776. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by sending specially crafted requests with OGNL expressions embedded in the URL path, often targeting endpoints ending in .action such as /help.action or /actionChain1.action, to achieve remote code execution on vulnerable Apache Struts2 servers.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2018-08-22
CISA KEV2021-11-03
CISA Remediation Deadline2022-05-03
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.