Skip to content
CVE-2015-3306 Exploited in ProFTPD FTP Servers

CVE-2015-3306 Exploited in ProFTPD FTP Servers

First seen 8 Oct 2026, 21:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 22:36 UTC
  • •CVE-2015-3306 is actively exploited, allowing unauthorized file access.
  • •Affected systems include ProFTPD 1.3.5, particularly those exposed to the internet.
  • •Immediate patching or mitigation is critical to prevent potential remote code execution.

CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active exploitation has been confirmed as of October 8, 2026, with proof-of-concept code available. Internet-facing ProFTPD deployments, especially legacy systems, are at the highest risk. Administrators are advised to review logs for suspicious activity and restrict FTP access to trusted networks. Immediate action is required to mitigate this threat, including upgrading to a patched version or disabling the vulnerable module.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2015-05-18
CVE-2015-3306 published
CVE-2015-3306 was published with a CVSS score of 10.0, indicating critical severity.
Redpacketsecurity
2026-10-08
CISA adds CVE-2015-3306 to KEV list
CISA confirmed active exploitation of CVE-2015-3306, urging immediate attention from affected organizations.
Redpacketsecurity
2026-10-08
Proof-of-concept code available
Publicly available exploit code allows attackers to leverage the vulnerability for unauthorized access.
Rapid7

More articles in this cluster (3)

Following this threat?

Track CVE-2015-3306 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of ProFTPD are affected?
ProFTPD version 1.3.5 is affected by CVE-2015-3306.
How urgent is the response to this vulnerability?
The vulnerability is critical and actively exploited, requiring immediate action to mitigate risks.
What should I do if I can't patch immediately?
Restrict FTP access to trusted networks and consider disabling the mod_copy module until a patch can be applied.