The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has heightened its security alerts by adding five newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This announcement, made on Thursday, follows confirmed reports of exploitation by Flax Typhoon, a threat group with links to China.
Identifying the Targeted Vulnerabilities
The identified vulnerabilities span various software systems and are rated with significant severity scores, emphasizing the urgency for mitigation. Among them, CVE-2015-3306 in ProFTPD scores a full 10.0 on the CVSS scale, highlighting its critical nature as it could permit unauthorized file access. Another, CVE-2021-3199 in ONLYOFFICE Docs, holds a 9.8 score, presenting a serious risk of remote code execution.
Additional vulnerabilities include CVE-2023-22894 in Strapi, which risks exposing sensitive information, and CVE-2016-3081 in Apache Struts, susceptible to command injection. Lastly, CVE-2015-5477 in ISC BIND could enable denial-of-service attacks.
International Cybersecurity Advisory
The acknowledgment of these vulnerabilities is part of a broader advisory released in collaboration with cybersecurity agencies from Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. This advisory warns that the Integrity Technology Group, a China-based cybersecurity entity, is leveraging these and other vulnerabilities for unauthorized access and data exfiltration.
These threats manifest through various tactics, including cross-site scripting and password spraying on Microsoft Exchange servers, aiming for persistence via VPN applications while extracting sensitive emails and credentials.
Broader Implications and Mandated Actions
Three additional vulnerabilities previously cataloged include CVE-2014-6278 (Shellshock), CVE-2019-11510, and CVE-2021-22205, underscoring the persistent threat landscape. CISA’s Acting Executive Assistant Director for Cybersecurity, Chris Butera, stressed the strategic infiltration of these actors into vital infrastructure, potentially disrupting future operations.
Given the active threat, federal agencies have been directed to implement the necessary patches by October 11, 2026, or cease using the affected systems to prevent further exploitation.
The urgency and international cooperation reflect the critical need for robust cybersecurity measures, particularly in safeguarding national infrastructure against sophisticated cyber threats.
