PatchDayAlert

Beat

Commentary

Critique and analysis of vendor patterns, framework guides, and the gap between security writing and operations.

Written by Colten Anderson.


Lead story

Two Apache Struts file upload CVEs, one incomplete fix, and the enterprise Java visibility problem

Analysis · Jun 18, 2026 · Colten Anderson

Two Struts CVEs, one incomplete fix, and the enterprise Java visibility problem

CVE-2023-50164 and CVE-2024-53677 hit the same file upload component in Apache Struts, a year apart.


More from this beat