Equifax and Apache Struts (2017)
Apache patched a critical RCE in its Struts framework (CVE-2017-5638) in March 2017. Equifax had not applied it; attackers exploited the flaw in May, stealing data on 147 million people. The breach was disclosed in September.
Equifax reached a settlement exceeding $1 billion and replaced its leadership.
The case became the standard example of a known, patchable RCE left unpatched in production.
The Forgejo postmortem told the same story: the fix was out for a week while the instance ran a version six months past end of life.
