elevated Cisa Kev · Exploits

CISA adds ONLYOFFICE Docs path traversal CVE-2021-3199 to KEV with a three-day deadline

Data graphic: CVSS 9.8 Critical ONLYOFFICE Docs CVE-2021-3199 added to CISA KEV, "A CVE from 2021, patched in August 2020, is now on CISA's KEV list, due 2026-10-11."
AK

Threat intelligence editor · Published Oct 9, 2026, 9:48 PM EDT

CISA added ONLYOFFICE Docs CVE-2021-3199, a CVSS 9.8 path traversal to RCE fixed in 5.6.3, to KEV on 2026-10-08. Federal due date: 2026-10-11.

CISA added CVE-2021-3199, a critical path traversal flaw in ONLYOFFICE Docs (Document Server) that can lead to remote code execution, to its Known Exploited Vulnerabilities catalog on 2026-10-08. The listing carries a due date of 2026-10-11. The fix shipped in Document Server 5.6.3 on 2020-08-17, about five months before NVD published the CVE on 2021-01-26, so any maintained deployment should be long past it. Older and forgotten instances are the concern.

What happened

CISA's KEV feed (catalog version 2026.10.08) lists ONLYOFFICE Docs under the name "ONLYOFFICE Docs Server Path Traversal Vulnerability". Its description says the flaw "can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution". The entry's ransomware field is "Unknown" and its forensic triage flag is "Yes".

CISA published no exploitation details with the listing: no reporting source, no actor, no victims and no indicators. KEV inclusion means CISA has evidence of exploitation, but that evidence is not public here. This article claims nothing beyond the listing.

The same day, CISA also added four other older CVEs, all with the same 2026-10-11 due date and "Unknown" ransomware use: Apache Struts CVE-2016-3081, ProFTPD CVE-2015-3306, ISC BIND CVE-2015-5477 and Strapi CVE-2023-22894.

Why it matters

NVD scores the flaw CVSS 3.1 9.8 (Critical): network attack vector, low complexity, no privileges, no user interaction. The three-day window follows from CISA's BOD 26-04, which applies to Federal Civilian Executive Branch agencies; for entries on the "3 days & forensic triage" tier it requires remediation or mitigation within three calendar days plus forensic analysis for signs of compromise. Private organizations are not bound by the directive, but KEV is widely used as a prioritisation list (we covered another KEV-listed WordPress core path traversal to RCE).

ONLYOFFICE Docs is often run as a separate server behind a file-sharing platform. The ONLYOFFICE Nextcloud connector, for example, states that you need "an instance of ONLYOFFICE Docs (Document Server) that is resolvable and connectable both from Nextcloud and any end clients". We found no source stating that any Nextcloud or ownCloud deployment has been attacked. The point is only that the Document Server is a separate component that may not be patched along with the platform it serves.

Technical details

NVD describes the issue as directory traversal with remote code execution in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, through a /.. sequence in an image upload parameter. The weakness is CWE-22. NVD's configuration lists onlyoffice:document_server with versions before 5.6.3 as affected. Traversal bugs reaching code execution are not limited to office software; see our write-up of the Ollama /api/pull path traversal.

Data graphic: timeline of CVE-2021-3199. Fixed in Document Server 5.6.3 on 2020-08-17, published in NVD 2021-01-26, added to CISA KEV 2026-10-08, due 2026-10-11 3 days , with four other old CVEs added the same day.

Fixed in 2020, given a 3-day KEV deadline: CVE-2021-3199 was patched in August 2020 but only reached CISA's KEV list in October 2026.

The vendor changelog for 5.6.3 records the fix as "Fix Path Traversal vulnerability via image upload params (Bug #46113)". GitHub's releases API dates 5.6.3 to 2020-08-17, which is about five months before NVD published the CVE (2021-01-26). The two preceding releases also fixed path traversal issues, in the savefile parameter (5.6.2, 2020-08-07) and the Convert Service parameter (5.6.1, 2020-08-05), so deployments on any release before 5.6.3 should be treated as carrying a series of traversal bugs, not one.

NVD lists a public proof-of-concept script for this CVE, under two GitHub URLs that resolve to the same repository (see Sources). We did not review it and do not reproduce it. We found no vendor advisory beyond the changelog and no independent technical write-up.

What defenders should do

  • Find every ONLYOFFICE Docs or Document Server instance, including those embedded in Nextcloud or other collaboration stacks and those deployed as containers. Check the running version.
  • Upgrade anything before 5.6.3. The latest release is v9.4.0 (2026-05-19), so a 5.x instance is several major versions behind. Follow ONLYOFFICE's upgrade path rather than expecting a single package bump.
  • If an instance cannot be updated now, remove it from direct internet exposure or restrict access to the integrating application only. BOD 26-04 itself says "one valid mitigation is to remove the system from the internet".
  • Treat exposed pre-5.6.3 instances as possibly compromised until checked. Look for unexpected files written outside the intended upload locations, unexplained processes spawned by the Document Server service, and unusual requests to /upload in web or proxy logs. These are general triage steps, not indicators published by CISA.
  • Federal agencies should follow BOD 26-04 and CISA's forensic triage requirements for this entry.

What is still unclear

  • Why a CVE from 2021, patched in August 2020, was added now. CISA's entry does not say, and any explanation would be inference. One reasonable reading is that CISA has seen recent exploitation of unpatched legacy instances, but nothing we found confirms that.
  • Who is exploiting it, against what targets, and whether ransomware operators are involved. CISA lists ransomware use as Unknown.
  • Whether exploitation depends on specific JWT configurations beyond the "when JWT is used" condition in the NVD text.

Sources

Keep reading

All latest →
  1. highExploitsSplunk Enterprise search head clusters exposed to critical unauthenticated RCE in Patroni API (CVE-2026-76268)5 min
  2. criticalExploitsAtlassian Patches Unauthenticated File Read CVE-2026-21589 Across Eight Data Center Products7 min
  3. highExploitsCitrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month's Patch Does Not Cover It5 min
  4. watchExploitsNext.js Dev Server MCP Flaw CVE-2026-94486 Lets Malicious Sites Read Source Snippets and Logs5 min
  5. elevatedExploitsWindows Cross Device flaw gives local users SYSTEM, with a public PoC5 min
  6. criticalExploitsArista VeloCloud Orchestrator Exploited at CVSS 10.0, With No Fix Listed for Two Release Trains4 min