CVE-2015-3306 ProFTPD file read added to CISA KEV, due 11 October
mod_copy SITE CPFR and CPTO still exploited on exposed FTP

CVE-2015-3306 ProFTPD file read added to CISA KEV, due 11 October

CISA added CVE-2015-3306 to the Known Exploited Vulnerabilities catalog on 8 October 2026. The bug is 11 years old. It is being used now. Federal agencies have a remediation date of 11 October 2026.

What happened

ProFTPD 1.3.5's mod_copy module lets a remote attacker read and write arbitrary files with the SITE CPFR and SITE CPTO commands. CISA scores the issue as improper access control and notes that the product line may be end of life. No login is required when the module is present.

The same day, CISA, FBI, and NSA published AA26-281A on Integrity Technology Group and Flax Typhoon. The advisory lists CVE-2015-3306 among vulnerabilities those actors successfully exploited, and marks it as newly added to KEV. Companion additions the same day include CVE-2015-5477 (ISC BIND denial of service), CVE-2016-3081 (Apache Struts command injection), CVE-2021-3199 (ONLYOFFICE Docs path traversal, CVSS 9.8), and CVE-2023-22894 (Strapi cleartext user data).

Who is affected

Anyone still running ProFTPD 1.3.5, or any later build that left mod_copy reachable from the internet. File-transfer servers in front of web roots, backup shares, or OT jump hosts are the practical risk. The other four KEV additions matter if you still run old BIND, Struts with Dynamic Method Invocation, ONLYOFFICE Document Server 5.1.5 through 5.6.2, or Strapi up to 4.5.5.

  • ProFTPD: unauthenticated file read and write via SITE CPFR and SITE CPTO.
  • Due date on the KEV entry: 11 October 2026.
  • CISA also requires forensic triage under BOD 26-04, not a patch-and-forget close.
  • Public exploit material for this bug has existed since 2015. Age is not a defense.

What to do now

Find every internet-facing FTP service this week, disable mod_copy, and isolate anything you cannot upgrade. Then hunt for unexpected files in web roots and for CPFR or CPTO in FTP logs. Treat ONLYOFFICE and old Struts the same way if they are exposed. A KEV addition this old means the scanner traffic is already commodity.

Source: CISA Known Exploited Vulnerabilities Catalog print view, updated 8 October 2026, KEV catalog. Related advisory: AA26-281A.

Red Lion N-Tron 700: seven flaws, upgrade to firmware 3.11.1
CISA ICSA-26-281-01 hardcoded credentials and unauthenticated SNMP