CISA added CVE-2016-3081 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 October 2026. The vulnerability affects Apache Struts and could let a remote attacker execute arbitrary code when Dynamic Method Invocation is enabled.
Apache describes CVE-2016-3081 as a command injection vulnerability. The attack uses `method:prefix` in an application with Dynamic Method Invocation enabled, potentially allowing remote code execution. The CVSS score is 8.1, rated HIGH. Patch status is unknown in the available data, and no patch or advisory URL is listed. Organisations should consult Apache’s security information for details.
KEV inclusion indicates that CISA has confirmed active exploitation. Whether attackers have used this vulnerability in ransomware campaigns is unknown. CISA set 11 October 2026 as the remediation deadline for affected federal agencies.
CISA requires organisations to apply mitigations in accordance with vendor instructions, follow applicable BOD 26-04 guidance for security updates and cloud services, and meet CISA’s Forensics Triage Requirements. If mitigations are unavailable, organisations should discontinue use of the product. Stakeholders must assess each asset’s internet exposure and comply with BOD 26-04 patching guidance.
Federal Civilian Executive Branch (FCEB) agencies are directly subject to CISA’s requirements; all organisations should review their exposure and take appropriate action.
For full details, see the [NVD entry](https://nvd.nist.gov/vuln/detail/CVE-2016-3081) and [CISA KEV catalogue](https://www.cisa.gov/known-exploited-vulnerabilities-catalog).