high Cisa Kev · Exploits

CISA adds four old Struts, ProFTPD, BIND and Strapi flaws to KEV, tied to China-linked intrusions

Data graphic: A timeline from 2015 to October 2026 showing four years-old flaws ProFTPD, BIND, Struts and Strapi added to CISA's KEV list on 2026-10-08, more than 11 years after the ProFTPD fix was merged on 2015-04-07. The federal due date is 2026-10-11.
AK

Threat intelligence editor · Published Oct 11, 2026, 4:45 PM EDT

CISA added Struts, ProFTPD, BIND and Strapi bugs to KEV on 8 Oct, due 11 Oct. Advisory AA26-281A ties them to China-linked actors; here is what to patch.

CISA added four old vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on 8 October 2026 and gave federal civilian agencies until 11 October, three days, to act. The flaws are in Apache Struts (CVE-2016-3081), ProFTPD (CVE-2015-3306), ISC BIND (CVE-2015-5477) and Strapi (CVE-2023-22894). The KEV entries name no actor and list ransomware use as "Unknown". A joint advisory published the same day, AA26-281A, does supply context: it says Chinese government-linked actors enabled by Integrity Technology Group successfully exploited all four. Anyone still running these products, or a vendor appliance that embeds them, is exposed.

A fifth addition from the same advisory, ONLYOFFICE Docs CVE-2021-3199, is covered separately in our earlier report.

What the advisory says

AA26-281A, issued by agencies in Australia, Canada, Japan, New Zealand, Spain, the UK and the US, describes actors using automated scanning, botnets and hands-on exploitation to steal data from organizations worldwide, including US critical infrastructure. Its Appendix B lists "successfully exploited" CVEs recovered from the actors' scanning scripts; these four are marked as newly added to KEV. The advisory says the activity is consistent with the publicly tracked clusters Flax Typhoon, Ethereal Panda and Red Juliett, and cautions that vendor tracking names do not map 1:1 to the US government's own methodology. (We covered a separate KEV case with a suspected Chinese-speaking actor, Zyxel GS1900 switch exploitation.)

One tool matters for this story. The advisory describes "MicroScan", a Python web application with more than 1,300 scripts, in use "as early as 2017", that checks sites for specific vulnerabilities, with Apache Struts among its named targets. Old bugs stay useful because scanners keep testing for them, and forgotten servers keep answering.

Data graphic: dumbbell chart of four CISA KEV additions, all added on 2026-10-08, showing how long ago each was fixed, disclosed or published. ProFTPD runs 11.5 years from its 2015-04-07 fix merge, BIND 11.2 years from its 2015-07-28 disclosure, Struts 10.5 years from its 2016-04-26 publication, and Strapi 3.6 years from its 2023-03-15 patch.

Four old flaws, one KEV date

The four flaws

Apache Struts, CVE-2016-3081 (S2-032). Remote code execution through the method: prefix when Dynamic Method Invocation (DMI) is enabled. Apache's bulletin lists Struts 2.3.20 through 2.3.28 as affected, except 2.3.20.3 and 2.3.24.3, and says to upgrade to 2.3.20.3, 2.3.24.3 or 2.3.28.1, or to disable DMI. NVD scores it 8.1 High (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). NVD's description gives wider ranges that start at 2.3.19. A Metasploit module and an Exploit-DB entry are referenced from NVD.

ProFTPD, CVE-2015-3306. The mod_copy module in ProFTPD 1.3.5 lets remote clients read and write arbitrary files through the SITE CPFR and SITE CPTO commands. The ProFTPD tracker shows the patch was merged on 7 April 2015 (bug 4169, comments 1–2) and shipped in 1.3.5a on 28 May 2015 (GitHub tag v1.3.5a), and 1.3.6rc1 carries it too. The patch also added a CopyEngine directive to switch the module off at runtime. NVD records a CVSS 2.0 score of 10.0, and CISA's ADP entry gives 10.0 under CVSS 3.1. Rapid7's Metasploit module, published in April 2015, describes unauthenticated use to copy files with the service's privileges and reach PHP code execution on hosts that also run a web server. We are not reproducing exploit steps.

ISC BIND, CVE-2015-5477. A crafted TKEY query triggers a REQUIRE assertion failure, and named exits. ISC's advisory lists BIND 9.1.0 through 9.8.x, 9.9.0 through 9.9.7-P1 and 9.10.0 through 9.10.2-P2 as affected, with fixes in 9.9.7-P2 and 9.10.2-P3. Both recursive and authoritative servers are vulnerable, and ACLs or configuration options do not help because the faulty code runs early in packet handling. ISC listed no workaround. The impact is denial of service only; ISC scored it 7.8 under CVSS 2.0, and NVD lists CISA's 7.5 under CVSS 3.1.

Strapi, CVE-2023-22894. Strapi's query filter can be used to infer values from private fields, including password hashes and password reset tokens. Strapi lists versions from 3.2.1 up to but not including 4.8.0 as affected, and says 4.8.0 (released 15 March 2023) fixes it. Strapi 3.x reached end of life on 31 December 2022 and gets no patch. Chained with CVE-2023-22621, a template-injection flaw fixed in 4.5.6, the vendor says the result is unauthenticated remote code execution on servers at 4.5.5 or earlier. KEV carries the same chaining warning and an end-of-life notice.

Why two scores for Strapi

NVD's own score is 4.9 Medium (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N), which assumes an attacker already holds admin access and can only read data. A 7.2 High (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) is attached to the record by CISA's ADP container, not by the CVE's assigner, which is MITRE and published no metrics. Strapi's own advisory uses a vector with no privileges required (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting the chain. The scores differ because each assumes a different starting position for the attacker. Version bounds differ as well: NVD's description and the CISA advisory say "through 4.5.5", while NVD's configuration data and the vendor say below 4.8.0. Treat anything below 4.8.0 as affected.

What defenders should do

  • Inventory first. Find Struts 2.3.x applications, ProFTPD hosts (distribution builds older than 1.3.5 can carry mod_copy too, for example Debian 7's 1.3.4a, fixed in 1.3.4a-5+deb7u3 under DSA-3263-1, so check whether mod_copy is loaded, not just the version), BIND 9.9 and 9.10 resolvers and nameservers, and Strapi installs. Check embedded copies and appliances; KEV notes that these components can sit inside other products.
  • Struts: upgrade, or disable DMI as Apache advises.
  • ProFTPD: confirm the build is 1.3.5a or later. If mod_copy is not needed, do not load it. Distributions backport fixes, so check the package changelog, not only the version string.
  • BIND: confirm 9.9.7-P2, 9.10.2-P3 or any newer supported release. Because ACLs do not mitigate it, version is the only control.
  • Strapi: move to a supported 4.x release, at least 4.8.0. Search request logs with the vendor's pattern for filter brackets on email, password and resetPasswordToken; hits mean rotate credentials and start incident response.
  • Hunt, do not just patch. KEV marks the Struts, ProFTPD and Strapi entries as requiring forensic triage. The advisory's IOCs are published as STIX files.
  • Follow the advisory's wider advice: disable unused services, enforce MFA, and replace end-of-life products.

Open points

CISA does not say which victims were hit through which flaw, and the KEV ransomware field is "Unknown" for all four. The advisory calls the activity consistent with Flax Typhoon, not identical to it.

Sources

Keep reading

All latest →
  1. highExploitsCitrix NetScaler CVE-2026-107406: Critical SAML Flaw Reaches Last Week's Patched IdP Builds8 min
  2. highExploitsThree Unauthenticated Root RCEs Hit Cisco Nexus 3000 and 9000: Check Which Feature Is On6 min
  3. highExploitsSplunk Enterprise search head clusters exposed to critical unauthenticated RCE in Patroni API (CVE-2026-76268)5 min
  4. criticalExploitsAtlassian Patches Unauthenticated File Read CVE-2026-21589 Across Eight Data Center Products7 min
  5. highExploitsCitrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month's Patch Does Not Cover It5 min
  6. watchExploitsNext.js Dev Server MCP Flaw CVE-2026-94486 Lets Malicious Sites Read Source Snippets and Logs5 min