I have yet to see any credible source pinpointing the CVE used to compromise the Equifax data (we all know it's in Struts, but which one was it?). Has something changed, or is this title clickbait?
https://www.equifaxsecurity2017.com
^ the official site, despite looking like a phish
There might be more to it, but this vulnerability was definitely used.