https://seclists.org/oss-sec/2026/q1/52: CVE-2025-68493: Apache Struts: XXE vulnerability in outdated XWork component
Published Jan 12, 2026
·Updated
Affected Software
1 affected component
Apache Struts
Frequently Asked Questions
1
What is the severity of CVE-2025-68493?
CVE-2025-68493 has a high severity rating due to its potential to allow XML External Entity (XXE) attacks.
2
How do I fix CVE-2025-68493?
To fix CVE-2025-68493, update to the latest version of Apache Struts that addresses this XXE vulnerability.
3
What systems are affected by CVE-2025-68493?
CVE-2025-68493 affects systems running outdated versions of the XWork component in Apache Struts.
4
What type of vulnerability is CVE-2025-68493?
CVE-2025-68493 is an XML External Entity (XXE) vulnerability that arises from insecure defaults in Java's standard library.
5
When was CVE-2025-68493 published?
CVE-2025-68493 was published on January 12, 2026.