Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On , CISA entered five vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog, attributing their exploitation to the Chinese threat actor Flax Typhoon. Federal civilian executive branch agencies have until to patch or decommission affected systems — a 72-hour window that turns flaws known for years into an immediate operational risk.
- Three of the five vulnerabilities are over five years old: CVE-2015-3306 (ProFTPD) carries a CVSS 10.0, the maximum possible score
- CISA's KEV catalog invokes BOD 26-04 with mandatory forensic triage for four of the five CVEs, excluding CVE-2015-5477 (ISC BIND)
- The Flax Typhoon operation targets eight vulnerabilities total: the five new KEV entries plus three previously cataloged (Shellshock, Ivanti, GitLab)
- A joint advisory from seven nations (Five Eyes, Japan, Spain) sanctions Integrity Technology Group, a Chinese cybersecurity company
The Technical Profile of the Five Flaws: From RCE to DoS
The attack surface covered by the five CVEs is exceptionally broad, reflecting an opportunistic approach that prioritizes internet exposure over a specific technology stack.
CVE-2015-3306 affects the mod_copy module in ProFTPD 1.3.5. The official CVE.org record confirms a remote attacker can read and write arbitrary files via the SITE CPFR and SITE CPTO commands. The CVSS 3.1 score is 10.0, the maximum possible value, with a network vector, low attack complexity, no privileges required, and impact across all three pillars of the CIA triad.
CVE-2021-3199 hits ONLYOFFICE Docs. The path traversal vulnerability exploits a /.. sequence in an image upload parameter when JSON Web Token (JWT) is enabled, resulting in remote code execution. The CVSS is 9.8.
CVE-2023-22894 concerns Strapi: cleartext storage of sensitive information that exposes user data through filter queries in the admin panel. With a CVSS of 7.2, it is the least severe of the set, but CISA notes it can be chained with CVE-2023-22621 to achieve RCE.
CVE-2016-3081 in Apache Struts enables command injection via the method: prefix when Dynamic Method Invocation is enabled (CVSS 8.1). CVE-2015-5477 in ISC BIND causes denial of service via malformed TKEY queries (CVSS 7.5). For the latter, CISA does not require forensic triage.
Vintage Vulnerabilities as Current Weapons: The Patch Debt Paradox
The striking data point is the temporal distribution: a flaw from 2015, one from 2016, one from 2021, and two from 2023. CVE-2015-3306 is nearly 11 years old, outlasting entire infrastructure planning cycles, yet remains present in exposed federal environments.
The mechanism is well known to threat analysts: sophisticated APTs build arsenals on obsolete vulnerabilities precisely because legacy assets remain in production beyond their security end-of-life. Flax Typhoon's sophistication — positioning in OT networks, persistence via VPN software, exfiltration of email and credentials — rests on technically trivial flaws. The contrast is deliberate: the actor invests in access and persistence, not zero-day research.
Chris Butera, CISA's Acting Executive Assistant Director for Cybersecurity, stated:
"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing."
The statement, released alongside the KEV update, frames the operation in the broader context of preparation for potential future disruption, not immediate attack.
The Joint Advisory and Integrity Technology Group
The CISA move coincides with a joint advisory issued by Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States. The document describes attacks "enabled" by Integrity Technology Group, a Chinese cybersecurity company sanctioned by Washington and London.
The wording is precise: the advisory speaks of attacks made possible by the company's infrastructure, not directly identifying Integrity Technology Group as Flax Typhoon. This distinction matters for geopolitical reading: it describes a support ecosystem for intelligence operations rather than a nominal coincidence between a commercial entity and a threat actor.
What to Do Now
- Check for the presence of ProFTPD 1.3.5, ONLYOFFICE Docs with JWT, Strapi with exposed admin panel, Apache Struts with Dynamic Method Invocation, or ISC BIND in your internet-facing attack surfaces
- For federal agencies subject to BOD 26-04: complete applicable patching or documented decommissioning by Oct. 11, 2026, with forensic triage for the four CVEs that require it
- Reprioritize patch management: vulnerabilities with high CVSS scores and ages exceeding five years demand active verification of presence, not just scanning of new disclosures
- Check for the three CVEs already in KEV that round out Flax Typhoon's documented arsenal: CVE-2014-6278 (Shellshock), CVE-2019-11510 (Ivanti Pulse Secure), CVE-2021-22205 (GitLab)
The Limits of the Dossier and Open Questions
The brief does not specify the current patch status from affected vendors, nor the availability of weaponized exploits for all five CVEs. CVE-2015-3306 has a confirmed exploit-db record, but analogous details do not emerge for the other four. The precise timeline of when Flax Typhoon began exploitation remains undocumented: CISA has cataloged active exploitation, not when it started.
The dossier contains no estimates of how many federal organizations are actually exposed, nor confirmations of compromises already achieved through these specific flaws. Operational impact remains potential but unquantified.
For private organizations not subject to BOD 26-04, the Oct. 11 deadline carries no binding force. However, KEV inclusion with confirmed nation-state exploitation turns these vulnerabilities into context-independent priority indicators.
The signal CISA sends with a 72-hour deadline is clear: the distinction between "old" and "new" vulnerabilities is operationally irrelevant when an APT is exploiting them. The required reaction time — two business days — is incompatible with traditional change management cycles. Critical infrastructure operators must assume the exposure window is what counts, not the CVE publication date.
Information verified against cited sources and current as of publication.
Sources
- https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html
- https://blog.netmanageit.com/flax-typhoon-exploits-five-flaws-as-cisa-sets-october-11-deadline-for-federal-agencies/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.vulncheck.com/blog/flax-typhoon-botnet
- https://nvd.nist.gov/general/news/cisa-exploit-catalog
- https://www.cve.org/CVERecord?id=CVE-2015-3306
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.