Back to Newsroom
Threat Intel

Flax Typhoon: Five Old Flaws Added to CISA's Exploited List, Federal Patch Deadline Is Today

CISA has added ProFTPD, ONLYOFFICE, Strapi, Apache Struts and ISC BIND flaws to KEV after confirming that the China-linked group Flax Typhoon is exploiting them. Here's what to check and fix.

Flax Typhoon: Five Old Flaws Added to CISA's Exploited List, Federal Patch Deadline Is Today

Flax Typhoon: Five Old Flaws Added to CISA's Exploited List, Federal Patch Deadline Is Today

CISA has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming that the China-linked group Flax Typhoon is actively exploiting them. U.S. federal civilian agencies must patch the affected products, or take them offline, by 11 October 2026. Some of these bugs are more than ten years old. They still work because the software they affect is often left running long after anyone stops watching it.

What happened

The new KEV entries cover a broad mix of everyday infrastructure:

CVEProductIssueCVSS
CVE-2015-3306ProFTPDImproper access control: unauthenticated file read/write through the SITE CPFR / SITE CPTO commands (mod_copy)10.0
CVE-2021-3199ONLYOFFICE DocsPath traversal (/..) in an image-upload parameter when JWT is in use, which can lead to remote code execution9.8
CVE-2016-3081Apache Struts 2Command injection through the method: prefix when Dynamic Method Invocation is enabled8.1
CVE-2015-5477ISC BINDReachable assertion that crashes named via TKEY queries (denial of service)7.5
CVE-2023-22894StrapiSensitive user data stored in cleartext and exposed through the admin-panel query filter7.2

CISA added the entries alongside a joint advisory from the United States, Australia, Canada, Japan, New Zealand, Spain and the United Kingdom. The advisory links the activity to Integrity Technology Group, a China-based cybersecurity company. According to the advisory, the operations relied on eight vulnerabilities in total: the five above plus three that were already in KEV:

  • CVE-2014-6278: GNU Bash command injection (Shellshock family)
  • CVE-2019-11510: Ivanti Pulse Connect Secure arbitrary file read
  • CVE-2021-22205: GitLab CE/EE remote code execution

The agencies describe a familiar playbook. The attackers use automated scanning to find exposed services, cross-site scripting, and password spraying against Microsoft Exchange to get in. They keep access by installing VPN software and use scripts to steal email and credentials. CISA says the wider aim is to gain positions inside critical infrastructure, including operational technology (OT) networks, that could be used for disruption later.

Why it matters

None of these flaws is new, and that is the problem. Old FTP daemons, forgotten Struts applications, DNS servers that were never upgraded, and self-hosted collaboration or CMS tools tend to sit outside regular patch cycles. These are exactly the internet-facing systems a well-resourced actor checks first. The federal deadline formally applies only to U.S. agencies, but KEV is the best public list of what attackers are using right now. Any organisation running these products should treat it as a deadline too.

What to do

  1. Inventory first. Search your external attack surface for ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts 2, ISC BIND, Pulse Connect Secure and GitLab, including test, preprod and "temporary" hosts.
  2. Patch or retire. Upgrade each to a fixed release. If a system can't be patched, take it off the internet or decommission it.
  3. Turn off risky features. Disable ProFTPD mod_copy if you don't need it, and disable Struts Dynamic Method Invocation.
  4. Harden Exchange and remote access. Enforce MFA, apply lockout and monitoring against password spraying, and watch for unusual sign-in patterns.
  5. Hunt for persistence. Look for VPN clients or tunnelling tools you didn't install, unexpected scripts, and unusual mailbox exports or outbound data transfers.
  6. Assume older compromise. If any of these systems were exposed and unpatched, review their logs for the full period of exposure, not only the last few days.

Source: reporting by The Hacker News; official details in CISA's Known Exploited Vulnerabilities catalog.

SHARE