Skip to content
CISA Adds 7 Flaws to KEV Amid Active Exploitation by Flax Typhoon

CISA Adds 7 Flaws to KEV Amid Active Exploitation by Flax Typhoon

First seen 11 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 18:31 UTC
  • •CISA added seven new flaws to its KEV catalog on October 11, 2026.
  • •Five vulnerabilities linked to the Flax Typhoon group are actively exploited.
  • •Organizations are advised to use both CVSS and CISA KEV for effective vulnerability management.

On October 11, 2026, CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, increasing the total to 1,739. Notably, five of these vulnerabilities were linked to the China-based group Flax Typhoon, which has been exploiting bugs since 2015. The vulnerabilities, including CVE-2021-3199 and CVE-2015-3306, were confirmed to be actively exploited, highlighting the gap between theoretical severity and real-world exploitation. The Common Vulnerability Scoring System (CVSS) scores for these flaws remained unchanged, emphasizing the need for organizations to prioritize based on active exploitation rather than just CVSS scores. Security teams are urged to adopt a dual approach using both CVSS and CISA KEV to effectively manage vulnerabilities. The current landscape shows that relying solely on CVSS can lead to misprioritization and increased costs for organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2015-04-21
Public exploit for CVE-2015-3306 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2021-01-22
CVE-2021-3199 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-19
CVE-2023-22894 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-104286 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-88779 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-08
CISA adds vulnerabilities to KEV
CISA confirmed the addition of multiple vulnerabilities, including CVE-2021-3199 and CVE-2015-3306, to its KEV list due to active exploitation.
Homeland411
2026-10-11
CISA updates KEV catalog
CISA added seven more flaws to its KEV catalog, bringing the total to 1,739 entries, emphasizing the importance of prioritizing vulnerabilities based on active exploitation.
Shattered

More articles in this cluster (2)

Following this threat?

Track Flax Typhoon and CVE-2015-3306 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which vulnerabilities were added to the KEV?
CISA added seven vulnerabilities, including CVE-2021-3199 and CVE-2015-3306, which are actively exploited.
What is the significance of the CVSS scores?
CVSS scores indicate theoretical severity but do not reflect active exploitation, which is critical for prioritizing patches.
How should organizations respond to these vulnerabilities?
Organizations should prioritize patching based on active exploitation and utilize both CVSS and CISA KEV for effective vulnerability management.