Apache has fixed a root privilege escalation vulnerability in its popular web server software, which runs on millions of servers.
There is a serious flaw in the file upload component in the Struts 2.3.x framework that can lead to remote code execution on vulnerable apps.
The original vulnerability may be in a jQuery plugin, but the disconnect in how web developers use .htaccess with the Apache web server and how the server is actually configured means there are potentially more applications out there that are vulnerable to attack.
The Mirai and Gafgyt IoT botnets recently have begun adding exploits for vulnerabilities in enterprise products.