CISA has put five more vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog. The Hacker News reports that the additions followed exploitation by a China-linked actor it calls Flax Typhoon. The NVD records for all five give 2026-10-08 as the catalog date and 2026-10-11 as the federal remediation deadline. Agencies therefore have only days to patch or stop using the affected products.
The affected software is ProFTPD (CVE-2015-3306), ONLYOFFICE Document Server (CVE-2021-3199), Apache Struts (CVE-2016-3081), ISC BIND (CVE-2015-5477) and Strapi (CVE-2023-22894). According to The Hacker News, the listings coincide with a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the U.K. and the U.S. That advisory concerns attacks attributed to a China-based cybersecurity company, Integrity Technology Group.
The five flaws
The technical details below come from the NVD records.
- ProFTPD, CVE-2015-3306 (CVSS 10.0, CWE-284). The
mod_copymodule in ProFTPD 1.3.5 allows remote attackers to read and write arbitrary files via thesite cpfrandsite cptocommands. The vector isCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H: network-reachable, no privileges or user interaction, changed scope. The CVE Program record was published on 2015-05-18 and last updated on 2021-05-26. Among its 14 references are public exploit materials, including a Rapid7 module namedexploit/unix/ftp/proftpd_modcopy_execand Exploit-DB entries 36803 and 36742. - ONLYOFFICE Document Server, CVE-2021-3199 (CVSS 9.8, CWE-22). Versions before 5.6.3 are affected when JWT is in use. Sending a
/..sequence in an image-upload parameter to/uploadcauses directory traversal that can lead to remote code execution. - Apache Struts, CVE-2016-3081 (CVSS 8.1, CWE-77). Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1 and 2.3.25 to 2.3.28 are affected when Dynamic Method Invocation is enabled. A remote attacker can execute arbitrary code through the
method:prefix, in a flaw tied to chained expressions. NVD's product list also names Oracle Siebel E-Billing 7.1. - ISC BIND, CVE-2015-5477 (CVSS 7.5, CWE-19, CWE-617). Crafted TKEY queries can crash
namedin BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3. The result is aREQUIREassertion failure and daemon exit. The impact is denial of service, not code execution. - Strapi, CVE-2023-22894 (CVSS 4.9, CWE-312). The NVD description covers Strapi through 4.5.5, and the product entry lists versions before 4.8.0. An attacker with admin-panel access can abuse the query filter to infer sensitive user data from API responses. With super-admin access, that reaches the password hash and password-reset token of every user. With an admin account that can view usernames and emails of lower-privileged API users such as Editors or Authors, the exposure extends to all API users, though not to other admin accounts.
The Hacker News gives the Strapi flaw a CVSS score of 7.2, while the NVD record says 4.9, with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. The scores for the other four match across the two sources.
What the joint advisory describes
The Hacker News says the advisory covers eight vulnerabilities in total, the five above plus three already in KEV. Per that report, the activity uses these flaws to gain initial access to organizations and take sensitive data. The described methods include scanning tools, cross-site scripting, and password spraying against Microsoft Exchange servers. Persistence is set up through VPN software, and emails and credentials are exfiltrated with scripts.
The reporting does not say that Flax Typhoon and Integrity Technology Group are the same entity, so the two names stay separate here. It also gives no figures on victims, sectors or geographies.
The Hacker News also quotes Chris Butera, CISA's Acting Executive Assistant Director for Cybersecurity. He said Chinese government-affiliated actors "continue to position themselves within critical infrastructure networks," including operational technology (OT) systems. He described the aim as disrupting critical functions at a future time of their choosing.
What agencies must do
All five KEV records carry the same instruction. Agencies are to apply mitigations according to vendor instructions, in line with CISA's BOD 26-04, "Prioritizing Security Updates Based on Risk", and its "Forensics Triage Requirements". For cloud services they follow the applicable BOD 26-04 guidance. If mitigations are unavailable, CISA's text says to discontinue use of the product. The record also makes stakeholders responsible for assessing each asset's internet exposure and keeping to the BOD 26-04 patching guidelines.
Anyone outside the federal government can use the version boundaries above to check their own estate:
- ProFTPD 1.3.5 installations.
- ONLYOFFICE Document Server below 5.6.3.
- Struts deployments with Dynamic Method Invocation enabled.
- BIND builds older than 9.9.7-P2 (9.9.x) or 9.10.2-P3 (9.10.x).
- Strapi below 4.8.0.
Three flaws already in the catalog
The Hacker News says the other three vulnerabilities in the advisory were already listed:
- CVE-2014-6278, a GNU Bash command-injection flaw (CVSS 8.8, CWE-78). It entered KEV on 2025-10-02 with a federal deadline of 2025-10-23. NVD describes it as stemming from an incomplete fix for CVE-2014-6271, the original Shellshock bug, as well as for CVE-2014-7169 and CVE-2014-6277. The first two have been in KEV since 2022-01-28, each with a 2022-07-28 deadline.
- CVE-2019-11510, an arbitrary file read in Ivanti Pulse Connect Secure, added in November 2021.
- CVE-2021-22205, remote code execution in GitLab Community and Enterprise Edition, also added in November 2021.




