A decade-old Apache Struts bug just landed on the US 'actively exploited' list
CVE-2016-3081 is nearly ten years old, but CISA says it's being exploited right now — here's who actually needs to care.
The headline claim
CISA, the US government’s cybersecurity agency, has added CVE-2016-3081 — a vulnerability in Apache Struts — to its Known Exploited Vulnerabilities (KEV) catalogue. That list exists for one reason: to flag bugs that aren’t just theoretically dangerous but are confirmed to be used by attackers in the wild. CISA’s own guidance states exploitation here is “confirmed, not theoretical,” which is a stronger claim than the usual “could be exploited” language you see with most vulnerability disclosures.
US federal civilian agencies have been given until 11 October to patch or mitigate, under a binding operational directive that only applies to government networks. That’s a regulatory deadline for Washington, not a global one — but KEV listings are widely treated by security teams everywhere as a reliable signal of “this is being actively abused, prioritise it.”
What’s actually known here
The bare facts, straight from CISA and NIST’s National Vulnerability Database: the affected vendor is Apache, the product is Struts, a widely used open-source framework for building Java web applications. The entry doesn’t specify ransomware involvement — CISA lists that field as “unknown” — and the public-facing catalogue text doesn’t spell out the exact exploitation method or which threat actors are behind it.
What’s notable, and worth flagging rather than glossing over, is the age of the flaw. CVE-2016-3081 has existed in the public record since 2016. Its sudden appearance on an actively-exploited list nearly a decade later isn’t unheard of — old, unpatched software is a perennial target precisely because defenders assume it’s “already dealt with” — but it’s a reminder that a patch being available for years doesn’t mean every installation has applied it.
So who is actually at risk
This is squarely an enterprise and server-side issue, not something that touches a home PC, phone or games console. Apache Struts runs behind the scenes in corporate and government web applications — the kind of software that powers internal systems, portals and backend services, not consumer apps you’d install directly. If you’re not a system administrator, developer or IT security professional, there is nothing here for you to personally patch or configure.
The people who do need to pay attention are organisations — particularly US federal agencies, who are compelled to act by the deadline — still running an old or unpatched Struts deployment. Given the CVE’s age, any organisation affected has likely either already patched years ago or has a legacy system that’s been quietly running unmaintained in the background, which is usually the more worrying scenario.
What to do about it
CISA’s advice is unglamorous but correct: apply Apache’s official mitigations or updates for the affected Struts versions, following standard vendor patching guidance. There’s no consumer action required, no app to update on your phone, and no need to change passwords because of this specific listing.
The takeaway
This is a case of a known, old vulnerability being confirmed as currently exploited rather than a brand-new threat appearing out of nowhere. It matters a great deal to anyone running affected enterprise infrastructure, and effectively not at all to everyday device users. The sensible response, if you’re not managing a Struts deployment yourself, is simply to note that it’s being handled by the people whose job that is — and move on.