Netskope Threat Labs

SERVER-APACHE Apache Struts OGNL getRuntime.exec static method access attempt

IPS-NPA

1 SID: 47634

First seen
July 2025
Last seen
September 2026

Detects an attempt to exploit CVE-2013-2134, CVE-2013-2135, and CVE-2018-11776, an expression language injection flaw that can allow code execution in Apache Struts. The flaw saw mass exploitation against internet-facing Struts servers.