U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
October 11, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2015-3306 (CVSS score of 10.0) – An access control flaw in ProFTPD that could let remote attackers read or modify arbitrary files by abusing the SITE CPFR and SITE CPTO commands.
  • CVE-2021-3199 (CVSS score of 9.8) – A path traversal flaw in ONLYOFFICE Docs when JSON Web Token (JWT) is enabled. Attackers could exploit a /.. sequence in an image upload parameter to potentially execute code remotely.
  • CVE-2023-22894 (CVSS score of 7.2) – A vulnerability in Strapi that exposes sensitive information stored in cleartext. An attacker with admin panel access could use query filters to retrieve confidential user details.
  • CVE-2016-3081 (CVSS score of 8.1) – A command injection flaw in Apache Struts that could allow remote attackers to run arbitrary code through method: prefixes when Dynamic Method Invocation is enabled.
  • CVE-2015-5477 (CVSS score of 7.5) – A reachable assertion vulnerability in ISC BIND that could be triggered by remote TKEY queries, potentially causing a denial-of-service condition.

The five vulnerabilities have been added to a broader list of flaws linked to cyber operations attributed to China-linked actors associated with Integrity Technology Group, a China-based cybersecurity company. The update coincides with a joint advisory issued by Australia, Canada, Japan, New Zealand, Spain, the United Kingdom and the United States. U.S. authorities have also taken action against tools associated with Integrity Tech and used in cyber espionage operations.

The activity reportedly involved the exploitation of eight vulnerabilities, including the five listed above, to gain initial access to targeted networks and steal sensitive information. The attackers used scanning tools, cross-site scripting (XSS) and password-spraying attacks against Microsoft Exchange servers. They also relied on VPN software to maintain access and scripts to extract emails and credentials.

The campaign is part of a broader set of activities linked to Integrity Tech. The U.S. Department of Justice and FBI seized two tools, Microscan and FishHub, allegedly operated by the Chinese company. Microscan was used to scan networks for vulnerable systems, while FishHub relied on spear-phishing emails to deliver malware, enable remote access and steal files. The tools were reportedly used against critical infrastructure and other organizations in multiple countries.

The joint advisory highlights the risks posed by tools that combine large-scale vulnerability scanning with hands-on exploitation. The coordinated action by seven countries and the U.S. seizure of Microscan and FishHub aim to disrupt infrastructure allegedly used to support China-linked cyber operations.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by October 11, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.