CISA added five Flax Typhoon-exploited flaws to the KEV catalog, with a federal patch deadline of October 11.
CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after abuse by China-linked Flax Typhoon: CVE-2015-3306 (ProFTPD), CVE-2021-3199 (ONLYOFFICE Docs), CVE-2023-22894 (Strapi), CVE-2016-3081 (Apache Struts), and CVE-2015-5477 (ISC BIND). A joint advisory from Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. attributes related intrusions to Integrity Technology Group and notes three already-listed KEV bugs: CVE-2014-6278, CVE-2019-11510, and CVE-2021-22205. Operators scanned for flaws, used cross-site scripting and Microsoft Exchange password spraying, persisted via VPN software, and scripted theft of emails and credentials. Federal agencies must remediate or discontinue use by October 11, 2026; CISA warned of pre-positioning in critical infrastructure and OT networks.
CISA put five flaws in the KEV catalog after Flax Typhoon exploitation.
U.S. federal agencies must patch or discontinue use by October 11, 2026.
Seven-country advisory ties the activity to Integrity Technology Group.
Campaign used scanning, XSS, Exchange password spraying, and VPN persistence.
Actors are described as pre-positioning in critical infrastructure and OT networks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.
The vulnerabilities in question are listed below -
CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CVE-2021-3199 (CVSS score: 9.8) - A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution.
CVE-2023-22894 (CVSS score: 7.2) - A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
CVE-2016-3081 (CVSS score: 8.1) - A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
The addition of the five vulnerabilities coincides with a joint advisory released by Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group.
These operations have been found to target eight security vulnerabilities, including the five listed above, to obtain initial access to organizations and siphon sensitive data. The activity involves exploiting flaws using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts.
CVE-2014-6278 - GNU Bash operating system command injection vulnerability (aka Shellshock) (Added in October 2025)
CVE-2019-11510 - Ivanti Pulse Connect Secure arbitrary file read vulnerability (Added in November 2021)
CVE-2021-22205 - GitLab Community and Enterprise Edition remote code execution vulnerability (Added in November 2021)
"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," said Acting Executive Assistant Director for Cybersecurity Chris Butera.
In light of active exploitation, federal agencies are required to apply the necessary patches or discontinue their use by October 11, 2026.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Remote OS Command Injection in GNU Bash via Crafted Environment (Shellshock-family)
GNU Bash, the standard command interpreter shipped with most Linux, Unix, and macOS systems, mishandles specially crafted environment variables, allowing attackers to inject and execute arbitrary OS commands (CVE-2014-6278 is one of the follow-on "Shellshock" parsing flaws disclosed in September 2014 alongside the original CVE-2014-6271). Exploitation requires a path where attacker-controlled data reaches Bash through the environment, classically via web CGI scripts, restricted or forced-command SSH configurations, DHCP clients, and other services that invoke the shell. A successful attack yields arbitrary command execution with the privileges of the invoking service, potentially leading to full system compromise. Any unpatched GNU Bash installation is affected, including Linux/Unix servers, macOS endpoints, and embedded or network appliances that bundle the shell. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-02, confirming exploitation in the wild, and EPSS assigns a 99.5% probability of exploitation within 30 days.
Do: Upgrade Bash to your distribution's or vendor's current patched build (all major Linux distributions and Apple shipped fixes after the September 2014 disclosures) and verify installed package versions rather than assuming patch status. Prioritize remediation on internet-facing systems where Bash may run with attacker-controlled environment variables, such as web/CGI servers, SSH forced-command setups, and embedded appliances, and follow CISA BOD 22-01 mitigation guidance per the KEV listing, or discontinue use if patches are unavailable. Hunt for legacy or embedded images that never received the 2014-era patches, since those are the most likely remaining vulnerable instances.
—
100%
KEV
GNU Bash
massmillions of installations, including hundreds of thousands of internet-exposed vulnerable hosts
Arbitrary file read/write via ProFTPD 1.3.5 mod_copy
The mod_copy module in ProFTPD 1.3.5 has an improper access control flaw (CWE-284) that lets remote attackers read and write arbitrary files. It is triggered by the SITE CPFR and SITE CPTO commands, which copy files without adequate authorization checks. An unauthenticated remote attacker can disclose or overwrite sensitive files and, with a CVSS 3.1 score of 10.0 and changed scope, can fully affect confidentiality, integrity, and availability. Systems running ProFTPD 1.3.5 with mod_copy, often internet-facing FTP servers, are affected. CISA lists it in the Known Exploited Vulnerabilities catalog (added 2026-10-08; ransomware use unknown), public proof-of-concept exploits exist, and EPSS is 96.8%.
Do: Upgrade or replace ProFTPD 1.3.5 per current vendor guidance, or disable the mod_copy module until that is done. Keep FTP off the public internet or limit it to trusted hosts, and review logs and filesystems for unexpected copies or overwrites. Apply CISA BOD 26-04 and forensics-triage requirements, and stop using the product if mitigations are unavailable.
Remote denial of service in ISC BIND via TKEY queries
A flaw in named, the DNS server in ISC BIND, lets a remote attacker crash the daemon by sending TKEY queries that trigger a REQUIRE assertion failure and force the process to exit. It is a data-processing error that reaches an assertion, needs no authentication or user interaction, and affects availability only. ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are affected. The issue is rated CVSS 3.1 7.5 (high), with an EPSS of about 91 percent. CISA lists it in the Known Exploited Vulnerabilities catalog, so exploitation in the wild is confirmed; ransomware use is unknown and no public proof-of-concept is recorded in the supplied data.
Do: Upgrade named to ISC BIND 9.9.7-P2 or later on the 9.9 branch, or 9.10.2-P3 or later on the 9.10 branch, and move to a currently supported BIND release because these 2015 branches are long obsolete. Prioritize internet-exposed resolvers and authoritative servers under CISA BOD 26-04, and stop using the product if a fix cannot be applied. After patching, review logs for unexpected named exits or REQUIRE assertion failures tied to TKEY queries.
7.5
99%
KEV
ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3
Command injection RCE in Apache Struts Dynamic Method Invocation
Apache Struts 2.3.19 through 2.3.20.2, 2.3.21 through 2.3.24.1, and 2.3.25 through 2.3.28 allow remote code execution when Dynamic Method Invocation is enabled. An attacker triggers the flaw over the network, without credentials or user interaction, by sending a request that uses a method: prefix and chained expressions, which the framework treats as commands (CWE-77). Successful exploitation gives arbitrary code execution with high impact to confidentiality, integrity, and availability. The listed Struts releases are affected, and Oracle Siebel e-billing is also identified via CPE as incorporating the component, though no Siebel versions are specified in the data. A public proof-of-concept is available, CISA lists the issue in the Known Exploited Vulnerabilities catalog (added 2026-10-08) so exploitation in the wild is confirmed, EPSS is about 93.4 percent, and ransomware use is unknown.
Do: Disable Dynamic Method Invocation if it is not required, and upgrade Apache Struts and products that embed it (including Oracle Siebel e-billing) to a release outside the affected 2.3.x ranges above, following vendor instructions and CISA BOD 26-04. Prioritize internet-exposed systems, review logs for method: prefix requests, and apply CISA forensics triage if compromise is suspected. Discontinue use if a fix or mitigation is unavailable.
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN
Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.
Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.
Unauthenticated RCE in GitLab CE/EE via ExifTool Image Parsing (CVE-2021-22205)
GitLab CE/EE versions from 11.9 onward fail to properly validate image files before passing them to the bundled ExifTool file parser, enabling command/code injection (CWE-94). A remote, unauthenticated attacker triggers it by getting the server to parse a specially crafted image (e.g., through file-upload features), with no credentials or user interaction required. Successful exploitation yields arbitrary command execution on the GitLab server, exposing source code, credentials, CI/CD data, and the wider network (CVSS 10.0, scope-changed). All self-managed GitLab Community and Enterprise Edition deployments on affected versions are exposed. The flaw is actively exploited in the wild: it is on CISA's KEV with known ransomware use, public PoCs exist, and 2021 campaigns used it for ransomware, cryptojacking, and access brokering against GitLab servers.
Do: Upgrade immediately to the patched releases - 13.10.3 or later, or the corresponding 13.9.6/13.8.6/13.7.9 backports - per vendor instructions, as required for KEV entries. Until patched, restrict network access to internet-facing GitLab instances and verify the bundled ExifTool is current. Hunt for signs of compromise (suspicious processes or cron jobs, cryptominers, webshells, new SSH keys, unexpected outbound connections), given documented ransomware and cryptojacking abuse.
ONLYOFFICE Document Server before 5.6.3 has a directory-traversal flaw (CWE-22) in the /upload function that can lead to remote code execution. When JWT is in use, a remote attacker can trigger it by placing a /.. sequence in an image-upload parameter, with no authentication or user interaction required. Successful exploitation can fully compromise confidentiality, integrity, and availability of the server (CVSS 3.1 base score 9.8). Self-hosted ONLYOFFICE Docs / Document Server installations older than 5.6.3 are affected. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2026-10-08, public proof-of-concept code is available, and ransomware use is listed as unknown.
Do: Upgrade ONLYOFFICE Document Server (ONLYOFFICE Docs) to version 5.6.3 or later and prioritize any internet-facing instances under CISA BOD 26-04. If a vendor fix cannot be applied, discontinue use of the product. Because this CVE is in the KEV catalog, review upload and application logs and the host for signs of path traversal or unexpected code execution and treat exposed unpatched servers as potentially compromised.
9.8
15%
KEV PoC ×2
ONLYOFFICE Document Server (ONLYOFFICE Docs) before 5.6.3
Sensitive-data leak in Strapi admin query filters (through 4.5.5)
CVE-2023-22894 is a sensitive-information disclosure flaw (CWE-312) in Strapi through version 4.5.5. An attacker who already has admin-panel access can use query filters on user records to infer values stored in sensitive columns from API responses. Super-admin access can reveal password hashes and password-reset tokens for all users; an admin who can view username and email of lower-privileged API users (such as Editor or Author) can expose sensitive details for those API users but not other admin accounts. The CVSS 3.1 score is 4.9 because confidentiality impact is high while high privileges are required. CISA lists it in the Known Exploited Vulnerabilities catalog (added 2026-10-08) with ransomware use unknown, and public write-ups exist.
Do: Upgrade Strapi to a release newer than 4.5.5 per the vendor security advisory, and limit admin-panel access to trusted accounts and networks with least privilege. If admin access may have been misused, rotate credentials, invalidate password-reset tokens, and review logs for unusual user queries. Apply CISA BOD 26-04 patching guidance for exposed assets, or discontinue use if a vendor fix cannot be applied.
thousands to low tens of thousands of internet-exposed ProFTPD hosts, unknown subset still on 1.3.5
KEV
on the order of 100,000–1,000,000+ DNS server installations
KEV
Apache Struts
2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled
Oracle Siebel e-billing
largetens of thousands of internet-facing Struts applications historically, with a larger enterprise install base
KEV
Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
KEV
GitLab Community Edition (CE) and Enterprise Edition (EE), self-managed All versions starting from 11.9 through versions prior to the vendor's April 2021 patch releases (fixed in 13.10.3, 13.9.6, 13.8.6, and 13.7.9)
largetens of thousands of internet-exposed self-managed GitLab instances (order of ~50,000+ servers in public scans)
KEV
KEV
large
on the order of 10,000–100,000 Strapi deployments (not all still on versions through 4.5.5)