Skip to content

CISA orders federal agencies to patch five flaws exploited by Flax Typhoon by Oct. 11

News.Lavx.Hu • October 9, 2026

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after the China-linked group Flax Typhoon used them to breach networks and steal data. Federal agencies must patch or retire the affected software by Oct. 11.

The U.S. Cybersecurity and Infrastructure Security Agency added five vulnerabilities to its Known Exploited Vulnerabilities catalog on Thursday after the China-linked hacking group Flax Typhoon exploited them to break into organizations and siphon off sensitive data.

The move triggers a federal remediation deadline. Agencies have until Oct. 11, 2026, to patch the flaws or stop using the affected products, under CISA's Binding Operational Directive 22-01.

The five newly listed vulnerabilities

Each of the flaws carries a serious severity rating, and several have been public for years, which makes the delayed patching across government networks notable.

CVE-2015-3306 (CVSS 10.0): An improper access control flaw in ProFTPD lets remote attackers read and write arbitrary files through the site cpfr and site cpto commands. A perfect severity score means any unauthenticated attacker who can reach a vulnerable server wins.

CVE-2021-3199 (CVSS 9.8): A path traversal bug in ONLYOFFICE Docs triggers when deployments use JSON Web Token authentication. Attackers plant a /../ sequence in an image upload parameter and land remote code execution.

CVE-2023-22894 (CVSS 7.2): Strapi stores sensitive information in cleartext, so an attacker with admin panel access can pull private user details through the query filter.

CVE-2016-3081 (CVSS 8.1): Apache Struts runs arbitrary code through the method:prefix parameter when Dynamic Method Invocation sits enabled. The setting ships off by default, yet decade-old Struts deployments still turn it on.

CVE-2015-5477 (CVSS 7.5): A reachable assertion in ISC BIND lets a remote attacker knock DNS resolvers offline with crafted TKEY queries.

A joint warning Integrity Technology Group

The catalog additions land alongside an advisory released Thursday by Australia, Canada, Japan, New Zealand, Spain, the U.K. and the U.S. The seven governments point the finger at Integrity Technology Group, a China-based cybersecurity company whose infrastructure underpins the attacks.

The advisory covers eight vulnerabilities in total. Five of them, listed above, are new to the KEV catalog. The other three joined the list earlier:

CVE-2014-6278 , the GNU Bash command injection bug better known as Shellshock, added in October 2025.

CVE-2019-11510 , an arbitrary file read in Ivanti Pulse Connect Secure, added in November 2021.

CVE-2021-22205 , a remote code execution flaw in GitLab, added in November 2021.

The pattern across all eight is old software facing the open internet. ProFTPD from 2015, Struts from 2016, Shellshock from 2014: these are products many organizations retired on paper while servers kept running in closets and cloud instances.

How the intrusions unfold

The joint advisory walks through the attack chain. Flax Typhoon operators scan for vulnerable internet-facing systems, then combine exploitation with cross-site scripting and password spraying against Microsoft Exchange servers to gain an initial foothold.

Once inside, they install VPN software to hold the door open, then run scripts that vacuum up email and credentials. The goal, according to the agencies, is persistent access to critical infrastructure networks, including operational technology systems that run physical equipment.

"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," said Chris Butera, acting executive assistant director for cybersecurity at CISA.

What defenders should do now

The Oct. 11 deadline binds federal agencies only, but the same advisories give any organization a concrete to-do list.

Start with an inventory pass. your network for ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and BIND. If a system runs one of these products on an internet-reachable interface, treat it as an emergency. Patch to the fixed version or decommission it.

Second, hunt for the access paths the advisory describes. Look for unauthorized VPN appliances and unfamiliar scheduled tasks on Microsoft Exchange servers. Review authentication logs for password spraying: bursts of failed logins against a single account, or many accounts hit from one source, in short windows.

Third, assume the catalog keeps growing. CISA's Binding Operational Directive 22-01 requires agencies to remediate listed vulnerabilities on a set clock, and the Flax Typhoon additions show how rarely a campaign uses a single flaw. Groups like this chain old, forgotten bugs with weak Exchange configurations. The CISA KEV catalog and the joint advisory published Thursday carry the full technical detail, including indicators of compromise.

Flax Typhoon has drawn sanctions and indictments before, and Integrity Technology Group's exposure in this advisory gives defenders something rare in state-linked espionage: named infrastructure to block. The five new KEV entries tell you exactly which doors to lock.

Source : thehackernews.com