CVE-2017-5638
ENISA EUVD: EUVD-2018-0625 ↗
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
8 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.27%
probability
This CVE has a 94.27% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS v3.1
Source: NVD9.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
Attack Intelligence
Exploits & PoC
mazen160/struts-pwn
An exploit for Apache Struts CVE-2017-5638
440
immunio/apache-struts2-CVE-2017-5638
Demo Application and Exploit
35
jas502n/st2-046-poc
st2-046-poc CVE-2017-5638
21
xsscx/cve-2017-5638
Example PoC Code for CVE-2017-5638 | Apache Struts Exploit
20
win3zz/CVE-2017-5638
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script
16
5 repos — triés par ⭐
Rechercher sur GitHub ↗
Apache Struts 2 Flaws Affect Multiple Cisco Products
TheHackerNews
Apache Struts Zero-Day Exploited in the Wild
BleepingComputer
Mar 09, 2017
Ransomware Gang Made Over $100,000 by Exploiting Apache Struts Zero-Day
BleepingComputer
Apr 06, 2017
Security Advisory 2017-005
CERT-EU
Mar 09, 2017
Signal Intelligence
Confidence
95%
EPSS
94.27%
CVSS v3.1
9.8
Mentions
8
Last Seen
Apr 06, 2017
CNA Information
Analyst Note
CVE-2017-5638 is a confirmed zero-day: the official description explicitly states it was 'exploited in the wild in March 2017,' which coincides with the CVE publication date (2017-03-11). This is a critical RCE in Apache Struts with CVSS 9.8, and exploitation occurred immediately upon disclosure.
Threat Actors 16
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Turla Group
apt_group
Information theft and espionage
Russian Federation
Void Arachne
apt_group
Information theft and espionage
🇨🇳 CN
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Prophet Spider
apt_group
UNKNOWN
Careto
apt_group
Information theft and espionage
🇪🇸 ES
Infy
apt_group
Information theft and espionage
🇮🇷 IR
GhostR
apt_group
🇨🇳 CN
Comment Crew
apt_group
Information theft and espionage
🇨🇳 CN
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
Bitwise Spider
apt_group
Financial gain
🇷🇺 RU
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Scarred Manticore
apt_group
Information theft and espionage
🇮🇷 IR
Triage Info
Decided atMar 05, 2026