VMTech
Discuss a project →

CISA adds five Flax Typhoon exploits to KEV catalog

CISA adds five Flax Typhoon exploits to KEV catalog

Five exploited flaws added to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities exploited by the China-linked Flax Typhoon threat actor to its Known Exploited Vulnerabilities (KEV) catalog. Federal civilian agencies must remediate the issues or discontinue use of the affected products by October 11, 2026.

The additions cover products used for file transfer, document collaboration, web applications, Java frameworks and DNS infrastructure: ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND. The five CVEs have severity scores ranging from 7.2 to 10.0.

Affected products and vulnerability details

  • CVE-2015-3306 in ProFTPD has a CVSS score of 10.0. Improper access control can allow remote attackers to read and write arbitrary files through the SITE CPFR and SITE CPTO commands.
  • CVE-2021-3199 in ONLYOFFICE Docs has a CVSS score of 9.8. When JSON Web Token authentication is used, a path traversal sequence in an image-upload parameter can lead to remote code execution.
  • CVE-2023-22894 in Strapi has a CVSS score of 7.2. An attacker with access to the administration panel may discover sensitive user details through a query filter because sensitive information is stored in cleartext.
  • CVE-2016-3081 in Apache Struts has a CVSS score of 8.1. Command injection is possible through method:prefix when Dynamic Method Invocation is enabled.
  • CVE-2015-5477 in ISC BIND has a CVSS score of 7.5. Crafted TKEY queries can trigger a reachable assertion and cause a denial of service.

Joint warning describes broader intrusion activity

The KEV update coincides with a joint advisory from authorities in Australia, Canada, Japan, New Zealand, Spain, the United Kingdom and the United States. The advisory attributes the activity to attacks enabled by the China-based cybersecurity company Integrity Technology Group.

The operations target eight vulnerabilities to gain initial access to organizations and siphon sensitive data. The other three CVEs—Shellshock in GNU Bash, an arbitrary file-read flaw in Ivanti Pulse Connect Secure, and a GitLab Community and Enterprise Edition remote-code-execution flaw—were already included in the KEV catalog.

The advisory describes the use of scanning tools, cross-site scripting and password spraying against Microsoft Exchange servers. It also says the operators establish persistence through VPN software and use scripts to exfiltrate emails and credentials.

What organizations should do

Acting Executive Assistant Director for Cybersecurity Chris Butera said Chinese government-affiliated actors continue to position themselves in critical-infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time.

For businesses, the practical implication is to inventory the named products, prioritize exposed and internet-facing deployments, apply available patches, and retire products that cannot be remediated. Security teams should also review VPN, Microsoft Exchange and email activity for the persistence and credential-exfiltration behavior described in the advisory.

#cybersecurity#vulnerabilitymanagement#threatintelligence#cisa
Open analytics
On the site 0 views
min read 3 09.10.2026
Instagram

CISA adds five Flax Typhoon exploits to KEV catalog

Open the post on Instagram ↗