Shattered CISA Adds 7 Flaws to KEV Amid Active Exploitation by Flax Typhoon
Article Content
- •CISA added seven new flaws to its KEV catalog on October 11, 2026.
- •Five vulnerabilities linked to the Flax Typhoon group are actively exploited.
- •Organizations are advised to use both CVSS and CISA KEV for effective vulnerability management.
On October 11, 2026, CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, increasing the total to 1,739. Notably, five of these vulnerabilities were linked to the China-based group Flax Typhoon, which has been exploiting bugs since 2015. The vulnerabilities, including CVE-2021-3199 and CVE-2015-3306, were confirmed to be actively exploited, highlighting the gap between theoretical severity and real-world exploitation. The Common Vulnerability Scoring System (CVSS) scores for these flaws remained unchanged, emphasizing the need for organizations to prioritize based on active exploitation rather than just CVSS scores. Security teams are urged to adopt a dual approach using both CVSS and CISA KEV to effectively manage vulnerabilities. The current landscape shows that relying solely on CVSS can lead to misprioritization and increased costs for organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Flax Typhoon and CVE-2015-3306 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which vulnerabilities were added to the KEV?
What is the significance of the CVSS scores?
How should organizations respond to these vulnerabilities?
Continue Reading
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…
Escalating Cyber Espionage Threats from China and Russia Cyber espionage has surged, with China and Russia leading state-sponsored attacks on sensitive data. In May 2025, the UK National Cyber Security Center linked breaches of the Electoral Commission to China, while Russian hackers targeted Tajikistan's educational and government sectors. Chinese cyber operations have…