
Table of contents
17
By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)
Read this in 30 seconds: CVE-2016-3081 is a command-injection bug in Apache Struts, reported in 2016, that lets a remote attacker run code on a server when Dynamic Method Invocation is enabled. CISA added it to its Known Exploited Vulnerabilities catalog on October 8, 2026, with a deadline of October 11 and a forensic-triage flag.
- The bug is old, but the flag is new. The Struts advisory dates from 2016. CISA’s catalog entry is dated October 8, 2026. The catalog does not say why it was added now.
- Apache and NVD disagree on the affected range. Apache lists 2.3.20 through 2.3.28, excluding two fixed releases. NVD starts at 2.3.19. Treat 2.3.19 as affected until you check it.
- The fix is an upgrade or a setting. Upgrade to 2.3.20.3, 2.3.24.3 or 2.3.28.1, or turn Dynamic Method Invocation off.
- Public exploit code exists. NVD’s references point to published exploits, so assume that attackers have what they need.
- Check your logs before you patch. CISA’s forensic-triage flag means evidence should be preserved first.
A bug from 2016 is still on the list because old software is still running, and the people running it often don’t know it is there.
Apache Struts is a Java web framework, and CVE-2016-3081 lives in its core. It powers enterprise applications, and many of those applications were built years ago and rarely rebuilt. That is the context for CVE-2016-3081, and it explains why a flaw this old can still matter.
This article covers what the bug is, which versions are affected, why the sources disagree, how to find it in your own estate, and what to do before you change anything.

Apache’s own bulletin, S2-032, describes the flaw directly. Attackers can pass a crafted expression that uses the method: prefix to run arbitrary code on the server. The bug applies only when Dynamic Method Invocation, or DMI, is enabled.
The bulletin credits Nike Zheng as the reporter, and rates the issue “Important.” It has a last-updated date of February 13, 2021, and does not give an original publication date in the page we read.
The NVD record carries the same weakness classification, CWE-77, which is command injection. NVD scores it CVSS 3.1 8.1 (High), with the vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, and CVSS 2 9.3. The 3.1 score’s attack complexity is marked high (AC:H). That means the attacker needs conditions to line up, and in this case the main condition is the DMI setting.
CISA’s catalog entry for CVE-2016-3081 is dated October 8, 2026. It carries a due date of October 11, the BOD 26-04 action text, a forensic-triage flag, and “Unknown” for known ransomware use. The entry’s notes link to Apache’s S2-032 page.
The catalog entry does not explain why CISA added a 2016 bug now. We looked, and we did not find a CISA statement or a vendor note that gives a reason. Several secondary aggregators list exploitation indicators, including exploit availability and a high predicted exploitation probability, but those are scoring services, not evidence of the events that prompted the listing.
We are therefore not going to tell you what changed. What we can say is that CISA considers the flaw exploited. Its entry points federal agencies to the BOD 26-04 deadline and forensic-triage guidance.
This is where the sources most often confuse people, so here is the comparison for CVE-2016-3081.
| Source | Affected range | Fixed releases |
|---|---|---|
| Apache S2-032 (primary) | 2.3.20 through 2.3.28, excluding 2.3.20.3 and 2.3.24.3 | 2.3.20.3, 2.3.24.3, 2.3.28.1 |
| NVD (primary for NVD) | 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, 2.3.25 to 2.3.28 | Not stated as a list in NVD’s description |
The two lists differ on whether 2.3.19 is affected. Apache’s bulletin starts at 2.3.20. NVD’s range starts at 2.3.19. We cannot resolve that from the sources we read, so our advice is conservative: treat 2.3.19 as affected until you have confirmed otherwise against your own build.
The fixed-release list is consistent across the sources we checked, and that is the line to act on. Check which release line you run, and move to the fixed release on that line.
Dynamic Method Invocation is a Struts feature that lets an application call a method named in the request. It is powerful, and that power is the problem. When DMI is on, the method: prefix in a crafted expression can be interpreted as an instruction to run code.
Security write-ups describe the setting that controls DMI as a constant named struts.enable.DynamicMethodInvocation, which can be set in struts.xml or struts.properties. We found that name only in secondary sources, not in Apache’s documentation, so confirm it against the reference for your exact release before you change anything.
Disabling DMI is a mitigation, not a fix. It removes the vulnerable path, and it is a sensible safeguard even on releases you have upgraded, because the same write-ups describe later releases where DMI being enabled still allows the same kind of expression. Upgrading is still the step that closes the bug on the release you run.
NVD’s reference list includes a public exploit on Exploit-DB, a Packet Storm entry for a Struts 2.3.28 exploit, and a Rapid7 module reference. Those references are the reason we say public exploit code exists, and it is the reason the bug is dangerous in practice.
We are not going to walk through how the exploit works. The advisory describes the bug class, and the fix is in the upgrade. What matters for defenders is that a working exploit is widely available, which means a version check is not a safe answer on its own. You need to confirm that the version you run is fixed, and that DMI is off or the fixed release is in place.
Most Struts applications carry the framework inside a packaged web archive, so the first job is inventory.
Start with the build files. Check pom.xml, build.gradle and any lock files for the struts2-core dependency and its version. Then check what is deployed, because the version in source control is not always the version running in production.
For a packaged archive, you can list its contents and look for the core jar:
# List the Struts core jar inside a deployed web archive
unzip -l app.war | grep struts2-core
The version is part of the jar’s file name, so read it straight from the listing. Anything at 2.3.19 through 2.3.28 needs review against the table above.
Next, check the DMI setting in your configuration. Look for the constant named above in struts.xml and struts.properties. A missing setting does not prove DMI is off, because the default depends on the release, so check the release’s documentation rather than assuming.
Finally, search your web server and application logs for the method: prefix in request parameters. This is our suggestion rather than a published indicator, and it will produce false positives, since legitimate content can contain the same text. Review every hit by hand.
CISA’s catalog flags CVE-2016-3081 for forensic triage. In practice that means you should preserve evidence before you patch, restart or rebuild anything, because a patch can overwrite the traces you need.
Before you change the application:
If the logs show method: requests that you cannot explain, treat it as a possible compromise, and escalate before you assume the patch closed it.
Work through these in order:
CVE-2016-3081 is a command-injection flaw in Apache Struts that lets a remote attacker run code on a server when Dynamic Method Invocation is enabled. It is reported in Apache’s S2-032 bulletin, and NVD classifies it as CWE-77.
CISA’s Known Exploited Vulnerabilities catalog lists it, with an entry dated October 8, 2026, a deadline of October 11 and a forensic-triage flag. The catalog does not explain why it was added now.
Apache lists 2.3.20 through 2.3.28, excluding 2.3.20.3 and 2.3.24.3. NVD starts its range at 2.3.19. Treat 2.3.19 as affected until you have confirmed otherwise.
Upgrade to 2.3.20.3, 2.3.24.3 or 2.3.28.1, depending on your release line. If you cannot upgrade, disable Dynamic Method Invocation, after checking the setting against your version’s documentation.
Preserve your logs, then search for method: in request parameters and review every hit by hand. Our search suggestion is not a published indicator of compromise, and a clean result does not prove the system is clean.
It removes the vulnerable path. Upgrading is still the step that closes the bug on the release you run, and the forensic check still applies if the system was exposed.
Old framework bugs are often found by inventory rather than by a new exploit. Knowing which applications run which versions, and whether the risky feature is on, is most of the work.
Our AI VAPT services combine automated and human-led testing against exposed applications, and the inventory and version review above is part of that kind of work. A pentest report documents what was tested and what was found. It does not certify that an application is free of this bug, and it does not replace the upgrade.
If you test your own applications with XHack AI, the findings carry a CVSS v4.0 rating, a CWE, references, proof and reproduction steps. Review each one yourself before it goes anywhere, because an automated tool can be wrong in either direction.
CVE-2016-3081 is a decade-old Struts flaw that CISA has now listed as exploited, with a deadline of October 11 and a forensic-triage flag. Public exploit code exists, and the affected range is wider in some sources than others.
Inventory your Struts versions, preserve the logs, and then upgrade to a fixed release or turn Dynamic Method Invocation off. The fix is not complicated. The hard part is finding every copy that is still running.
Categories
Related articles