Struts vulnerability hype train update: For what it’s worth, I haven’t seen any valid exploitation of this.
Also, if it helps anybody, Struts 1 isn’t vulnerable.
I’ve seen some vendors issue advisories saying they’re checking their products (eg Cisco). They may issue precautionary patches.
I haven’t seen any product vendors so far that actually ship in an exploitable unauthenticated condition.
It isn’t the 2017 Struts situation.