Thehackernews CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon
Article Content
- •CISA mandates patching of five critical vulnerabilities by October 11, 2026.
- •Flax Typhoon, a China-linked group, is exploiting these vulnerabilities for data breaches.
- •The vulnerabilities include CVE-2015-3306, CVE-2021-3199, and others with high severity ratings.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities include CVE-2015-3306 (CVSS 10.0), CVE-2021-3199 (CVSS 9.8), CVE-2023-22894 (CVSS 7.2), CVE-2016-3081 (CVSS 8.1), and CVE-2015-5477 (CVSS 7.5). These flaws have been public for years, raising concerns about delayed patching across government networks. The advisory highlights that the attacks are facilitated by a China-based cybersecurity company, Integrity Technology Group, which has been linked to the exploitation of eight vulnerabilities in total. The vulnerabilities allow for various attack vectors, including remote code execution and denial-of-service attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Flax Typhoon, Integrity Technology Group and CVE-2014-6278 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the specific vulnerabilities listed?
What is the deadline for patching?
Who is responsible for the attacks?
Continue Reading
Escalating Cyber Espionage Threats from China and Russia Cyber espionage has surged, with China and Russia leading state-sponsored attacks on sensitive data. In May 2025, the UK National Cyber Security Center linked breaches of the Electoral Commission to China, while Russian hackers targeted Tajikistan's educational and government sectors. Chinese cyber operations have…
State Actors Target New Zealand with Cyber Espionage State actors are conducting sophisticated cyber operations against New Zealand, primarily focused on espionage. These activities target both government and private sector organizations, with a notable emphasis on critical infrastructure such as energy, telecommunications, and transport networks. The National Cyber…