On 8 October 2026 CISA added five vulnerabilities to the Known Exploited Vulnerabilities catalog after abuse by the China-linked actor Flax Typhoon. Federal civilian agencies must patch or stop using the affected products by 11 October 2026. The same week, the FBI and Justice Department seized domains used to reach Integrity Technology Group tools MicroScan and FishHub.
What happened
A joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK and the US says China-based Integrity Technology Group enabled scanning and, in some cases, intrusions against critical infrastructure. Operators combined old public flaws, password spraying against Microsoft Exchange, VPN persistence, and scripts that pulled email and credentials. CISA's acting cyber lead said the actors keep positioning inside critical infrastructure, including operational technology, for possible later disruption.
The five newly listed bugs are old on purpose. Edge gear that still runs them is the point.
- CVE-2015-3306 (CVSS 10.0): ProFTPD improper access control, arbitrary file read and write via SITE CPFR and SITE CPTO
- CVE-2021-3199 (CVSS 9.8): ONLYOFFICE Docs path traversal to remote code execution when JWT is in use
- CVE-2023-22894 (CVSS 7.2): Strapi cleartext sensitive data via the admin query filter, up to 4.5.5
- CVE-2016-3081 (CVSS 8.1): Apache Struts command injection when Dynamic Method Invocation is enabled
- CVE-2015-5477 (CVSS 7.5): ISC BIND denial of service via crafted TKEY queries
Who is affected
Anyone still running those versions, not only US federal networks. The advisory also cites three older KEV entries already used in the same activity: CVE-2014-6278 (Shellshock), CVE-2019-11510 (Pulse Connect Secure) and CVE-2021-22205 (GitLab). Reported scan targets included a US power company, airports in Japan and Poland, and Taiwanese energy and university networks.
What to do now
Search asset inventories for ProFTPD 1.3.5, ONLYOFFICE Docs 5.1.5 through 5.6.2, Strapi through 4.5.5, Struts 2.3 with Dynamic Method Invocation on, and unpatched BIND 9.9 or 9.10. Patch or remove them. If any of those services faced the internet, assume credential and file theft is possible and rotate secrets that lived on the host. Domain seizures disrupt the tool portals. They do not evict an implant already inside a network.
Source: The Hacker News, Flax Typhoon exploits five flaws as CISA sets October 11 deadline. Primary advisory: CISA AA26-281A.
Also on the blog
- CVE-2026-102255 SonicWall SMA1000 SSRF Under Probe
- CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- Germany Arrests Alleged Qilin Ransomware Leader
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.