lukaszlenart opened a new pull request, #323: URL: https://github.com/apache/struts-site/pull/323
Adds the site announcements for the five security bulletins published on the cwiki today, 14 August 2026. | CVE | Bulletin | Fixed in | |---|---|---| | CVE-2026-73631 | [S2-070](https://cwiki.apache.org/confluence/display/WW/S2-070) | 7.3.0 | | CVE-2026-73632 | [S2-071](https://cwiki.apache.org/confluence/display/WW/S2-071) | 7.3.0 | | CVE-2026-73633 | [S2-072](https://cwiki.apache.org/confluence/display/WW/S2-072) | 7.3.0, 6.11.0 | | CVE-2026-73634 | [S2-073](https://cwiki.apache.org/confluence/display/WW/S2-073) | 7.3.0, 6.11.0 | | CVE-2026-73635 | [S2-074](https://cwiki.apache.org/confluence/display/WW/S2-074) | 7.3.0, 6.11.0 | `announce-2026.md` gets one dated entry per CVE, following the S2-068 and S2-069 form, so each can be linked on its own. All five share a date, so the anchors after the first are disambiguated (`a20260814-s2071` and onwards) the same way the 6.11.0 GA entry was. On the home page the first security box now points at the batch as a whole instead of a single bulletin, and the CVE-2025-68493 / S2-069 box moves into the slot held by S2-068, which is a year old. The `cve.org` record links are deliberately absent from the site copy — the records are `READY` but not yet pushed to MITRE, so those URLs 404 for now. The bulletins themselves carry the CVE identifiers. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
