Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on October 8, 2026, with a federal deadline of October 11. The three-day window granted to FCEB agencies to patch or decommission affected systems is exceptionally short, justified by confirmed active exploitation in a coordinated campaign by cyber actors associated with Integrity Technology Group, a Chinese cybersecurity company.
The five flaws affect ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND — open-source software widely deployed across global server infrastructure. Four of the five date from 2015–2021, with patches available for years. The campaign demonstrates that nation-state actors do not need zero-days to compromise critical targets.
- CISA added five CVEs to the KEV catalog on October 8, 2026, with a federal due date of October 11, per NVD records and the CISA bulletin.
- The vulnerabilities are CVE-2015-3306 (ProFTPD, CVSS 10.0), CVE-2021-3199 (ONLYOFFICE Docs, CVSS 9.8), CVE-2023-22894 (Strapi, CVSS 7.2), CVE-2016-3081 (Apache Struts, CVSS 8.1), and CVE-2015-5477 (ISC BIND, CVSS 7.5).
- Exploitation is attributed to Chinese actors associated with Integrity Technology Group, with a joint advisory issued by seven nations: Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States.
- Four of the five vulnerabilities require forensic triage under BOD 26-04; the sole exception is CVE-2015-5477 (ISC BIND), for which CISA does not impose that requirement.
The KEV Catalog and the 72-Hour Sprint
CISA's Known Exploited Vulnerabilities catalog does not simply list the most severe flaws; it documents those with confirmed evidence of in-the-wild exploitation. Inclusion triggers a mitigation mandate for FCEB agencies under BOD 22-01, with deadlines CISA calibrates based on severity and operational risk.
The October 11, 2026 deadline is among the tightest ever imposed. NVD records for CVE-2023-22894, CVE-2021-3199, and CVE-2016-3081 confirm the standard structure: "Date Added: October 08, 2026 | Due Date: October 11, 2026." Three days does not allow extended test cycles; it demands immediate patch application or removal of the system from the federal network.
Four of the five vulnerabilities also require the forensic triage mandated by BOD 26-04, meaning agencies must preserve system images and logs for subsequent analysis. The sole exception is CVE-2015-5477 in ISC BIND, for which CISA does not activate that requirement.
The Mechanics of Five Flaws: From Arbitrary Read/Write to Chained RCE
Each vulnerability presents a distinct technical profile, but all share the characteristic of affecting infrastructure components often managed with low maintenance priority.
CVE-2015-3306 in ProFTPD carries a CVSS 10.0, the maximum score. Security Affairs documents that the flaw allows arbitrary file read and write by abusing the SITE CPFR and SITE CPTO commands in the mod_copy module. The CVE.org record confirms the presence of the mod_copy module and cross-references to vendor advisories.
CVE-2021-3199 in ONLYOFFICE Docs has a CVSS 9.8 and is classified as a path traversal. Security Affairs reports that "/.." sequences in an image upload parameter can lead to remote code execution; CISA's KEV entry describes the flaw as enabling remote code execution.
CVE-2023-22894 in Strapi has a CVSS 7.2 and is the most recent of the batch. CISA KEV documents cleartext storage of sensitive information and the possibility of chaining with CVE-2023-22621 to achieve remote code execution. 7IT Solutions corroborates the exploitation chain.
CVE-2016-3081 in Apache Struts has a CVSS 8.1 and is a legacy flaw in the Java framework widely adopted for enterprise applications. Its reappearance in the 2026 KEV indicates unpatched installations still exposed to the internet.
CVE-2015-5477 in ISC BIND has a CVSS 7.5 and is the only one in the group for which CISA does not require forensic triage. The dossier does not specify whether this flaw was actually exploited in-the-wild in the campaign or included for contextual completeness.
Integrity Technology Group and the Seven-Nation Advisory
The geopolitical context distinguishes this KEV entry from a routine technical listing. The joint advisory from seven nations links exploitation of the five vulnerabilities to cyber operations attributed to Chinese actors. The Hacker News explicitly identifies the threat actor as Flax Typhoon. Security Affairs refers to actors associated with Integrity Technology Group. The CISA/FBI/NSA advisory describes TTPs consistent with Flax Typhoon, Ethereal Panda, and Red Juliett.
Integrity Technology Group is a Chinese cybersecurity company that, according to Western agencies, provides tool-as-a-service to threat actors. The Department of Justice and the FBI have seized two platforms: Microscan, for network scanning, and FishHub, for spear-phishing and malware distribution. The operation represents an escalation in public response: the targeting is no longer just the actor, but the commercial enabler.
"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing" — Chris Butera, Acting Executive Assistant Director for Cybersecurity, CISA
The FBI has confirmed the dual strategy. According to Brett Leatherman, Assistant Director of the FBI's Cyber Division: "Under the FBI Cyber Strategy, we pursue both the actors who threaten critical infrastructure and the enterprises that support them."
The Persistence of Open-Source Technical Debt
The most disturbing data point is chronological. Four of the five vulnerabilities are over three years old; two are nearly a decade old. CVE-2015-3306 and CVE-2015-5477 date to 2015: patches have been available for eleven years. Their presence in the 2026 KEV is not a responsible disclosure problem; it is an irresponsible adoption problem.
Infrastructure open-source software — FTP servers, DNS resolvers, headless CMSs, web frameworks — powers technology stacks that organizations often do not fully map. "Patch fatigue" combines with reduced visibility: components with no user interface, no direct revenue, no board attention. They remain in production until a nation-state actor highlights them.
The campaign documented by CISA confirms this attack surface is not theoretical. The actors employed scanning tools, cross-site scripting, password-spraying against Exchange, VPNs for persistence, and dedicated scripts for exfiltration. The Hacker News reports the operation involved eight total vulnerabilities: the five newly added to the KEV plus three already present (CVE-2014-6278, CVE-2019-11510, CVE-2021-22205).
What to Do Now
For organizations managing the affected products, priority actions derive directly from the dossier:
Apply the corresponding patches for the listed CVEs, verifying the current version against official vendor release notes. CISA KEV and NVD records document the fixed versions for each flaw.
Check for Strapi with CVE-2023-22621, given that CVE-2023-22894 can be chained with this second flaw to achieve RCE. The chain requires both components.
Conduct forensic triage for the four vulnerabilities that require it under BOD 26-04, preserving system images and logs for potential subsequent analysis.
Review posture on EOL systems: 7IT Solutions explicitly underscores the risk of end-of-life software, which receives no patches even when flaws are known.
The Lesson of Unapplied Patches
The contrast is stark: three days of federal reaction against eleven years of available patches. The speed of CISA's response demonstrates operational capability; the necessity of that response demonstrates systemic failure in infrastructure software management. The actors CISA links to Integrity Technology Group did not discover new flaws; they simply harvested those the market never closed.
The seizure of Microscan and FishHub, the seven-nation advisory, the explicit citation of OT systems in Chris Butera's quote: all signal the operation is not cataloged as ordinary cybercrime, but as strategic positioning in critical infrastructure. The question for decision-makers is no longer whether to patch, but why the patch was not already applied.
"Attackers don't need new bugs while old ones still pay. A 2015 CVE in production isn't legacy. It's an open door." — Lior Aharonov, 7IT Solutions
Sources
- https://securityaffairs.com/200734/security/u-s-cisa-adds-proftpd-onlyoffice-docs-strapi-apache-struts-and-isc-bind-flaws-to-its-known-exploited-vulnerabilities-catalog.html?amp
- https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html
- https://securityaffairs.com/200734/security/u-s-cisa-adds-proftpd-onlyoffice-docs-strapi-apache-struts-and-isc-bind-flaws-to-its-known-exploited-vulnerabilities-catalog.html
- https://7it.co.il/news/2026-10-09-cisa-kev-strapi-onlyoffice-struts/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cve.org/CVERecord?id=CVE-2015-3306
- https://nvd.nist.gov/vuln/detail/CVE-2023-22894
- https://nvd.nist.gov/vuln/detail/CVE-2021-3199
- https://nvd.nist.gov/vuln/detail/CVE-2016-3081
- https://www.cisa.gov/news-events/news/cisa-fbi-nsa-and-international-partners-warn-china-based-cybersecurity-company-enabling-threat
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.