Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

CISA gives federal agencies until October 11 to fix five old flaws Flax Typhoon exploited

CISA gave federal agencies until October 11 to fix five flaws China-linked Flax Typhoon has exploited, the oldest carrying 2015 CVE numbers. For other operators, each bug's preconditions decide which old servers need the patch first.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying CISA gives federal agencies until October 11 to fix five old flaws Flax Typhoon exploited
Generated illustration

What happened

  • ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND are the products behind the five new KEV entries.
  • A joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK and the US, released alongside the additions, warns of attacks enabled by China-based Integrity Technology Group.
  • Those operations target eight vulnerabilities, including all five new entries, to gain initial access to organizations and take sensitive data.
  • Of the other three, already in KEV, the Ivanti Pulse Connect Secure and GitLab bugs were listed in November 2021 and Shellshock in October 2025.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any ProFTPD server still on a vulnerable build is the widest opening of the five, since the flaw's description attaches no configuration condition to remote file read and write.
  • decision Struts and ONLYOFFICE owners can size their exposure with a configuration check first, because code execution depends on Dynamic Method Invocation being on or JWT being in use.
  • decision The BIND and Strapi bugs belong lower in a triage queue than their scores above 7 suggest: one crashes the server, the other needs an attacker already in the admin panel.

Sorted by what each bug gives an attacker who has only a network path, the five split three ways. ProFTPD's CVE-2015-3306 is improper access control in the site cpfr and site cpto commands, and it lets a remote attacker read and write arbitrary files [3]. Its CVSS score is 10.0 [3].

Two more reach code execution, each under a condition. The Apache Struts flaw, CVE-2016-3081, is command injection through the method: prefix and works when Dynamic Method Invocation is enabled [6]. The ONLYOFFICE Docs flaw, CVE-2021-3199, is path traversal through a "/.." sequence in an image upload parameter, and it occurs when JSON Web Token is used [4]. They score 8.1 and 9.8 respectively [6][4].

The remaining two have narrower effects. ISC BIND's CVE-2015-5477 is a reachable assertion triggered by TKEY queries, scored 7.5, and its listed outcome is denial of service [7]. Strapi's CVE-2023-22894, scored 7.2, is cleartext storage of sensitive user details that an attacker can pull through the query filter, but only with access to the admin panel [5].

Most of this is old code. Two of the five carry 2015 identifiers, eleven years before the October 2026 deadline [14]. Four of the five date to 2021 or earlier [15]. According to The Hacker News, the operations behind them start with scanning tools, add cross-site scripting and password spraying against Microsoft Exchange servers, set up persistence through VPN software, and use scripts to take email and credentials [10].

Chris Butera, the acting executive assistant director for cybersecurity, spoke more broadly. "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," Butera said [12]. His statement covers Chinese government-affiliated actors in general, and the report does not connect its operational technology warning to these eight flaws [9].

What to watch

  • Whether CISA or the advisory partners name sectors or victims reached through these five flaws, and how Flax Typhoon maps to Integrity Technology Group in their accounts.
  • Internet scan counts of ProFTPD, Struts and ONLYOFFICE servers still on vulnerable builds after the October 11 deadline.
  • Any explanation of what part the BIND denial-of-service flaw plays in an intrusion chain built for initial access.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    CISA on Thursday added five security flaws to its Known Exploited Vulnerabilities catalog following their abuse by a China-linked threat actor known as Flax Typhoon.

    ReportedSupportedSource: The Hacker News, reporting CISA's KEV additionsView cited source
  2. [2]

    The five flaws added are in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND.

    ReportedSupportedSource: The Hacker NewsView cited source
  3. [3]

    CVE-2015-3306 (CVSS 10.0) is an improper access control vulnerability in ProFTPD that could allow remote attackers to read and write arbitrary files via the site cpfr and site cpto commands.

    ReportedSupportedSource: The Hacker NewsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 9, 2026

    Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories