- CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after China-linked threat actor Flax Typhoon exploited them to target critical infrastructure
- The flaws affect ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND, with CVSS scores ranging from 7.2 to 10.0
- A joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK, and the US warned of attacks enabled by China-based cybersecurity company Integrity Technology Group
- Federal agencies must patch or discontinue use of affected software by October 11, 2026
The U.S. Cybersecurity and Infrastructure Security Agency added five security flaws to its Known Exploited Vulnerabilities catalog on Thursday, following their abuse by China-linked threat actor Flax Typhoon. The vulnerabilities range from 2015 to 2023, affecting widely deployed software including ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND.
The most severe flaw, CVE-2015-3306, carries a CVSS score of 10.0 and allows remote attackers to read and write arbitrary files via improper access control in ProFTPD. Meanwhile, CVE-2021-3199 enables remote code execution through a path traversal vulnerability in ONLYOFFICE Docs, and CVE-2023-22894 exposes sensitive user details via cleartext storage in Strapi.
The addition coincides with a joint advisory released by Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group. These operations have been found to target eight security vulnerabilities to obtain initial access to organizations and siphon sensitive data.
“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time of their choosing,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. Exploitation involves scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, with persistence established through VPN software and credential exfiltration using scripts.
Three related vulnerabilities already in the KEV catalog include CVE-2014-6278 (Shellshock), CVE-2019-11510 affecting Ivanti Pulse Connect Secure, and CVE-2021-22205 impacting GitLab. Federal agencies must apply patches or discontinue use by October 11, 2026.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
