Redpacketsecurity CVE-2015-3306 Exploited in ProFTPD FTP Servers
Article Content
- •CVE-2015-3306 is actively exploited, allowing unauthorized file access.
- •Affected systems include ProFTPD 1.3.5, particularly those exposed to the internet.
- •Immediate patching or mitigation is critical to prevent potential remote code execution.
CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active exploitation has been confirmed as of October 8, 2026, with proof-of-concept code available. Internet-facing ProFTPD deployments, especially legacy systems, are at the highest risk. Administrators are advised to review logs for suspicious activity and restrict FTP access to trusted networks. Immediate action is required to mitigate this threat, including upgrading to a patched version or disabling the vulnerable module.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2015-3306 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of ProFTPD are affected?
How urgent is the response to this vulnerability?
What should I do if I can't patch immediately?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…