CISA added CVE-2015-3306 to the Known Exploited Vulnerabilities catalog on 8 October 2026. The bug is 11 years old. It is being used now. Federal agencies have a remediation date of 11 October 2026.
What happened
ProFTPD 1.3.5's mod_copy module lets a remote attacker read and write arbitrary files with the SITE CPFR and SITE CPTO commands. CISA scores the issue as improper access control and notes that the product line may be end of life. No login is required when the module is present.
The same day, CISA, FBI, and NSA published AA26-281A on Integrity Technology Group and Flax Typhoon. The advisory lists CVE-2015-3306 among vulnerabilities those actors successfully exploited, and marks it as newly added to KEV. Companion additions the same day include CVE-2015-5477 (ISC BIND denial of service), CVE-2016-3081 (Apache Struts command injection), CVE-2021-3199 (ONLYOFFICE Docs path traversal, CVSS 9.8), and CVE-2023-22894 (Strapi cleartext user data).
Who is affected
Anyone still running ProFTPD 1.3.5, or any later build that left mod_copy reachable from the internet. File-transfer servers in front of web roots, backup shares, or OT jump hosts are the practical risk. The other four KEV additions matter if you still run old BIND, Struts with Dynamic Method Invocation, ONLYOFFICE Document Server 5.1.5 through 5.6.2, or Strapi up to 4.5.5.
- ProFTPD: unauthenticated file read and write via SITE CPFR and SITE CPTO.
- Due date on the KEV entry: 11 October 2026.
- CISA also requires forensic triage under BOD 26-04, not a patch-and-forget close.
- Public exploit material for this bug has existed since 2015. Age is not a defense.
What to do now
Find every internet-facing FTP service this week, disable mod_copy, and isolate anything you cannot upgrade. Then hunt for unexpected files in web roots and for CPFR or CPTO in FTP logs. Treat ONLYOFFICE and old Struts the same way if they are exposed. A KEV addition this old means the scanner traffic is already commodity.
Source: CISA Known Exploited Vulnerabilities Catalog print view, updated 8 October 2026, KEV catalog. Related advisory: AA26-281A.