SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
CISA gives federal agencies until October 11 to fix five old flaws Flax Typhoon exploited
CISA gave federal agencies until October 11 to fix five flaws China-linked Flax Typhoon has exploited, the oldest carrying 2015 CVE numbers. For other operators, each bug's preconditions decide which old servers need the patch first.
The Watch · Security desk

What happened
- ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND are the products behind the five new KEV entries.
- A joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK and the US, released alongside the additions, warns of attacks enabled by China-based Integrity Technology Group.
- Those operations target eight vulnerabilities, including all five new entries, to gain initial access to organizations and take sensitive data.
- Of the other three, already in KEV, the Ivanti Pulse Connect Secure and GitLab bugs were listed in November 2021 and Shellshock in October 2025.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any ProFTPD server still on a vulnerable build is the widest opening of the five, since the flaw's description attaches no configuration condition to remote file read and write.
- decision Struts and ONLYOFFICE owners can size their exposure with a configuration check first, because code execution depends on Dynamic Method Invocation being on or JWT being in use.
- decision The BIND and Strapi bugs belong lower in a triage queue than their scores above 7 suggest: one crashes the server, the other needs an attacker already in the admin panel.
Sorted by what each bug gives an attacker who has only a network path, the five split three ways. ProFTPD's CVE-2015-3306 is improper access control in the site cpfr and site cpto commands, and it lets a remote attacker read and write arbitrary files [3]. Its CVSS score is 10.0 [3].
Two more reach code execution, each under a condition. The Apache Struts flaw, CVE-2016-3081, is command injection through the method: prefix and works when Dynamic Method Invocation is enabled [6]. The ONLYOFFICE Docs flaw, CVE-2021-3199, is path traversal through a "/.." sequence in an image upload parameter, and it occurs when JSON Web Token is used [4]. They score 8.1 and 9.8 respectively [6][4].
The remaining two have narrower effects. ISC BIND's CVE-2015-5477 is a reachable assertion triggered by TKEY queries, scored 7.5, and its listed outcome is denial of service [7]. Strapi's CVE-2023-22894, scored 7.2, is cleartext storage of sensitive user details that an attacker can pull through the query filter, but only with access to the admin panel [5].
Most of this is old code. Two of the five carry 2015 identifiers, eleven years before the October 2026 deadline [14]. Four of the five date to 2021 or earlier [15]. According to The Hacker News, the operations behind them start with scanning tools, add cross-site scripting and password spraying against Microsoft Exchange servers, set up persistence through VPN software, and use scripts to take email and credentials [10].
Chris Butera, the acting executive assistant director for cybersecurity, spoke more broadly. "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," Butera said [12]. His statement covers Chinese government-affiliated actors in general, and the report does not connect its operational technology warning to these eight flaws [9].
What to watch
- Whether CISA or the advisory partners name sectors or victims reached through these five flaws, and how Flax Typhoon maps to Integrity Technology Group in their accounts.
- Internet scan counts of ProFTPD, Struts and ONLYOFFICE servers still on vulnerable builds after the October 11 deadline.
- Any explanation of what part the BIND denial-of-service flaw plays in an intrusion chain built for initial access.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA on Thursday added five security flaws to its Known Exploited Vulnerabilities catalog following their abuse by a China-linked threat actor known as Flax Typhoon.
- [2]
The five flaws added are in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND.
- [3]
CVE-2015-3306 (CVSS 10.0) is an improper access control vulnerability in ProFTPD that could allow remote attackers to read and write arbitrary files via the site cpfr and site cpto commands.
- [4]
CVE-2021-3199 (CVSS 9.8) is a path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token is used, via a "/.." sequence in an image upload parameter, and could allow remote code execution.
- [5]
CVE-2023-22894 (CVSS 7.2) is a cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
- [6]
CVE-2016-3081 (CVSS 8.1) is a command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method: prefix when Dynamic Method Invocation is enabled.
- [7]
CVE-2015-5477 (CVSS 7.5) is a reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial of service via TKEY queries.
- [8]
The KEV additions coincide with a joint advisory released by Australia, Canada, Japan, New Zealand, Spain, the U.K. and the U.S. warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group.
- [9]
The operations target eight security vulnerabilities, including the five added to KEV, to obtain initial access to organizations and siphon sensitive data.
- [10]
The activity involves exploiting flaws using scanning tools, cross-site scripting attacks and password spraying on Microsoft Exchange servers, setting up persistence through VPN software, and exfiltrating emails and credentials using scripts.
- [11]
The remaining three vulnerabilities were already in KEV: CVE-2014-6278 GNU Bash command injection (Shellshock), added October 2025; CVE-2019-11510 Ivanti Pulse Connect Secure arbitrary file read, added November 2021; CVE-2021-22205 GitLab CE/EE remote code execution, added November 2021.
- [12]
"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,"
ReportedSupportedSource: Chris Butera, Acting Executive Assistant Director for Cybersecurity, quoted by The Hacker NewsView cited source - [13]
Federal agencies are required to apply the necessary patches or discontinue use of the affected products by October 11, 2026.
- [14]
Two of the five flaws (CVE-2015-3306 in ProFTPD and CVE-2015-5477 in BIND) carry 2015 CVE identifiers, 11 years before the 2026 deadline year.
- [15]
Four of the five flaws carry CVE years of 2021 or earlier (2015, 2015, 2016, 2021); only the Strapi flaw is from 2023.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comFlax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- China State-Linked Cyber OperationsFollow
- Known Exploited Vulnerabilities catalogFollow
- Patch And Redeploy LatencyFollow