Skip to content
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon

CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon

First seen 9 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 16:35 UTC
  • •CISA mandates patching of five critical vulnerabilities by October 11, 2026.
  • •Flax Typhoon, a China-linked group, is exploiting these vulnerabilities for data breaches.
  • •The vulnerabilities include CVE-2015-3306, CVE-2021-3199, and others with high severity ratings.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities include CVE-2015-3306 (CVSS 10.0), CVE-2021-3199 (CVSS 9.8), CVE-2023-22894 (CVSS 7.2), CVE-2016-3081 (CVSS 8.1), and CVE-2015-5477 (CVSS 7.5). These flaws have been public for years, raising concerns about delayed patching across government networks. The advisory highlights that the attacks are facilitated by a China-based cybersecurity company, Integrity Technology Group, which has been linked to the exploitation of eight vulnerabilities in total. The vulnerabilities allow for various attack vectors, including remote code execution and denial-of-service attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2014-09-30
CVE-2014-6278 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2015-04-21
Public exploit for CVE-2015-3306 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2015-07-29
CVE-2015-5477 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2016-04-26
CVE-2016-3081 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-05-08
CVE-2019-11510 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-01-22
CVE-2021-3199 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-04-23
CVE-2021-22205 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-04-19
CVE-2023-22894 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-08
CISA adds vulnerabilities to KEV catalog
CISA added five vulnerabilities exploited by Flax Typhoon to its KEV catalog, triggering a patching deadline.
News.Lavx.Hu
2026-10-09
Federal agencies notified of patch deadline
CISA announced that federal agencies must patch or retire affected software by October 11, 2026.
Thehackernews

More articles in this cluster (8)

Following this threat?

Track Flax Typhoon, Integrity Technology Group and CVE-2014-6278 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the specific vulnerabilities listed?
The vulnerabilities include CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-2016-3081, and CVE-2015-5477.
What is the deadline for patching?
Federal agencies must patch or retire the affected software by October 11, 2026.
Who is responsible for the attacks?
The attacks are attributed to Flax Typhoon, a China-linked hacking group, with support from Integrity Technology Group.