Critical Apache Struts security flaw makes it 'easy' to hack Fortune 100 firms
zdnet.com
zdnet.com
"A RCE attack is possible when using the Struts REST plugin with XStream handler to deserialise XML requests" https://struts.apache.org/docs/s2-052.html
[1] https://struts.apache.org/announce.html#a20170905 for today's release announcement of 2.5.13 that fixes this plus two denial-of-service vulnerabilities.