CISA added Struts, ProFTPD, BIND and Strapi bugs to KEV on 8 Oct, due 11 Oct. Advisory AA26-281A ties them to China-linked actors; here is what to patch.
CISA added four old vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on 8 October 2026 and gave federal civilian agencies until 11 October, three days, to act. The flaws are in Apache Struts (CVE-2016-3081), ProFTPD (CVE-2015-3306), ISC BIND (CVE-2015-5477) and Strapi (CVE-2023-22894). The KEV entries name no actor and list ransomware use as "Unknown". A joint advisory published the same day, AA26-281A, does supply context: it says Chinese government-linked actors enabled by Integrity Technology Group successfully exploited all four. Anyone still running these products, or a vendor appliance that embeds them, is exposed.
A fifth addition from the same advisory, ONLYOFFICE Docs CVE-2021-3199, is covered separately in our earlier report.
What the advisory says
AA26-281A, issued by agencies in Australia, Canada, Japan, New Zealand, Spain, the UK and the US, describes actors using automated scanning, botnets and hands-on exploitation to steal data from organizations worldwide, including US critical infrastructure. Its Appendix B lists "successfully exploited" CVEs recovered from the actors' scanning scripts; these four are marked as newly added to KEV. The advisory says the activity is consistent with the publicly tracked clusters Flax Typhoon, Ethereal Panda and Red Juliett, and cautions that vendor tracking names do not map 1:1 to the US government's own methodology. (We covered a separate KEV case with a suspected Chinese-speaking actor, Zyxel GS1900 switch exploitation.)
One tool matters for this story. The advisory describes "MicroScan", a Python web application with more than 1,300 scripts, in use "as early as 2017", that checks sites for specific vulnerabilities, with Apache Struts among its named targets. Old bugs stay useful because scanners keep testing for them, and forgotten servers keep answering.
Four old flaws, one KEV date
The four flaws
Apache Struts, CVE-2016-3081 (S2-032). Remote code execution through the method: prefix when Dynamic Method Invocation (DMI) is enabled. Apache's bulletin lists Struts 2.3.20 through 2.3.28 as affected, except 2.3.20.3 and 2.3.24.3, and says to upgrade to 2.3.20.3, 2.3.24.3 or 2.3.28.1, or to disable DMI. NVD scores it 8.1 High (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). NVD's description gives wider ranges that start at 2.3.19. A Metasploit module and an Exploit-DB entry are referenced from NVD.
ProFTPD, CVE-2015-3306. The mod_copy module in ProFTPD 1.3.5 lets remote clients read and write arbitrary files through the SITE CPFR and SITE CPTO commands. The ProFTPD tracker shows the patch was merged on 7 April 2015 (bug 4169, comments 1–2) and shipped in 1.3.5a on 28 May 2015 (GitHub tag v1.3.5a), and 1.3.6rc1 carries it too. The patch also added a CopyEngine directive to switch the module off at runtime. NVD records a CVSS 2.0 score of 10.0, and CISA's ADP entry gives 10.0 under CVSS 3.1. Rapid7's Metasploit module, published in April 2015, describes unauthenticated use to copy files with the service's privileges and reach PHP code execution on hosts that also run a web server. We are not reproducing exploit steps.
ISC BIND, CVE-2015-5477. A crafted TKEY query triggers a REQUIRE assertion failure, and named exits. ISC's advisory lists BIND 9.1.0 through 9.8.x, 9.9.0 through 9.9.7-P1 and 9.10.0 through 9.10.2-P2 as affected, with fixes in 9.9.7-P2 and 9.10.2-P3. Both recursive and authoritative servers are vulnerable, and ACLs or configuration options do not help because the faulty code runs early in packet handling. ISC listed no workaround. The impact is denial of service only; ISC scored it 7.8 under CVSS 2.0, and NVD lists CISA's 7.5 under CVSS 3.1.
Strapi, CVE-2023-22894. Strapi's query filter can be used to infer values from private fields, including password hashes and password reset tokens. Strapi lists versions from 3.2.1 up to but not including 4.8.0 as affected, and says 4.8.0 (released 15 March 2023) fixes it. Strapi 3.x reached end of life on 31 December 2022 and gets no patch. Chained with CVE-2023-22621, a template-injection flaw fixed in 4.5.6, the vendor says the result is unauthenticated remote code execution on servers at 4.5.5 or earlier. KEV carries the same chaining warning and an end-of-life notice.
Why two scores for Strapi
NVD's own score is 4.9 Medium (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N), which assumes an attacker already holds admin access and can only read data. A 7.2 High (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) is attached to the record by CISA's ADP container, not by the CVE's assigner, which is MITRE and published no metrics. Strapi's own advisory uses a vector with no privileges required (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting the chain. The scores differ because each assumes a different starting position for the attacker. Version bounds differ as well: NVD's description and the CISA advisory say "through 4.5.5", while NVD's configuration data and the vendor say below 4.8.0. Treat anything below 4.8.0 as affected.
What defenders should do
- Inventory first. Find Struts 2.3.x applications, ProFTPD hosts (distribution builds older than 1.3.5 can carry
mod_copytoo, for example Debian 7's 1.3.4a, fixed in 1.3.4a-5+deb7u3 under DSA-3263-1, so check whethermod_copyis loaded, not just the version), BIND 9.9 and 9.10 resolvers and nameservers, and Strapi installs. Check embedded copies and appliances; KEV notes that these components can sit inside other products. - Struts: upgrade, or disable DMI as Apache advises.
- ProFTPD: confirm the build is 1.3.5a or later. If
mod_copyis not needed, do not load it. Distributions backport fixes, so check the package changelog, not only the version string. - BIND: confirm 9.9.7-P2, 9.10.2-P3 or any newer supported release. Because ACLs do not mitigate it, version is the only control.
- Strapi: move to a supported 4.x release, at least 4.8.0. Search request logs with the vendor's pattern for filter brackets on
email,passwordandresetPasswordToken; hits mean rotate credentials and start incident response. - Hunt, do not just patch. KEV marks the Struts, ProFTPD and Strapi entries as requiring forensic triage. The advisory's IOCs are published as STIX files.
- Follow the advisory's wider advice: disable unused services, enforce MFA, and replace end-of-life products.
Open points
CISA does not say which victims were hit through which flaw, and the KEV ransomware field is "Unknown" for all four. The advisory calls the activity consistent with Flax Typhoon, not identical to it.
Sources
- CISA KEV catalog JSON
- CISA advisory AA26-281A
- Apache Struts S2-032
- ISC advisory AA-01272 (Internet Archive copy)
- ProFTPD bug 4169
- Rapid7 Metasploit module, proftpd_modcopy_exec
- Strapi security disclosure
- NVD records: CVE-2016-3081, CVE-2015-3306, CVE-2015-5477, CVE-2023-22894
- CVE record CVE-2023-22894
- Debian security tracker, CVE-2015-3306