A critical, stubborn new vulnerability in Apache Struts 2 may be under active exploitation already, and fixing it isn't as simple as downloading a patch. Struts 2 is an open source framework for ...
I'm no Struts expert, but my guess is that Struts adds a Servlet Mapping for anything in the context that ends in .xml.