Abahlaseli bomhlaba wonke basebenzisa ngamandla ukuba sengozini okukhulu ku-Apache Struts 2, uhlaka oludumile lomthombo ovulekile lokuthuthukisa izinhlelo zokusebenza zewebhu ye-Java namawebhusayithi. Lesi sexwayiso sivela kuziphathimandla zase-Australia naseFrance ezilindele ukuhlukunyezwa okusabalele. I-Apache Foundation iphendule ngomhla ka-7 Disemba ngezibuyekezo zokuphepha zokubhekana nalokhu kuba sengcupheni, i-CVE-2023-50164.
Ngo-2017, iphutha elifanayo elibucayi ku-Struts lasetshenziswa ukuze kwebiwe idatha kubantu baseMelika abangaphezu kwezigidi ezingu-147 ehhovisi lezikweletu lase-US i-Equifax. Ukuba sengozini kwamanje okuxhashazwayo kuvumela abahlaseli ukuthi bashintshe imingcele yokulayisha ifayela. Lokhu kuholela ekunqamukeni komzila kanye nokulayishwa kwamafayela ayingozi, ekugcineni kuvumela ukwenziwa kwekhodi yesilawuli kude, lapho umhlaseli ezuza khona ukulawula phezu kwesistimu ethintekile.
Muva nje, i I-Shadowserver Foundation ibone ukuhlaselwa kusetshenziswa ikhodi yokuxhaphaza ethuthukiswe ngaphambilini yobufakazi bomqondo. I-Australian Cyber Security Center (ACSC), i-French Computer Emergency Response Team (CERT-FR), kanye nomdondoshiya we-inthanethi u-Akamai nabo babike ukusetshenziswa kabi. Iziphathimandla zeluleka izinhlangano ukuthi zibuyekeze izicelo zazo ezisekelwe ku-Struts njengoba zilindele ukuhlukumeza okubanzi. Ngalesi sintuba sokuvikeleka, abahlaseli bangafaka igobolondo le-backdoor noma lewebhu, okuvumela ukufinyelela okuzinzile kuseva eyonakele futhi kuvunyelwe eminye imisebenzi enonya.