Skip to main content
Threat IntelligenceEmerging Threats

CISA Warns of Flax Typhoon Exploiting Five Vulnerabilities

Control room with industrial controllers and equipment in neutral lighting.

"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," said Acting Executive Assistant Director for Cybersecurity Chris Butera.

CISA adds five vulnerabilities to the Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog after reporting that a China-linked threat actor known as Flax Typhoon has abused them. The move places those flaws under heightened scrutiny and invokes a federal remediation requirement tied to an October 11, 2026 deadline: federal agencies must apply the necessary patches or discontinue use of affected systems by that date.

The five CVEs and their technical profiles

  • CVE-2015-3306 (CVSS score: 10.0) — An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write arbitrary files via the site cpfr and site cpto commands.
  • CVE-2021-3199 (CVSS score: 9.8) — A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used; exploitation via a "/.." sequence in an image upload parameter could allow remote code execution.
  • CVE-2023-22894 (CVSS score: 7.2) — A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
  • CVE-2016-3081 (CVSS score: 8.1) — A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
  • CVE-2015-5477 (CVSS score: 7.5) — A reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.

Flax Typhoon, Integrity Technology Group, and the multi‑vulnerability campaign

The KEV additions follow a joint advisory issued by Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S., which linked the attacks to a China-based cybersecurity company named Integrity Technology Group. That advisory said the operations targeted eight vulnerabilities in total — including the five just added to the KEV catalog — to obtain initial access and siphon sensitive data.

The methods described in the advisory are multiple and opportunistic: attackers used scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers to gain footholds; they set up persistence through VPN software; and they exfiltrated emails and credentials using scripts. The advisory ties those tactics to the campaign and to the named China-based company as the enabling actor for the attacks.

Already-tracked flaws and the broader exploitation set

Three other vulnerabilities cited in the joint advisory were already in CISA’s KEV catalog prior to this update:

  • CVE-2014-6278 — GNU Bash operating system command injection vulnerability (Shellshock). Added to KEV in October 2025.
  • CVE-2019-11510 — Ivanti Pulse Connect Secure arbitrary file read vulnerability. Added to KEV in November 2021.
  • CVE-2021-22205 — GitLab Community and Enterprise Edition remote code execution vulnerability. Added to KEV in November 2021.

The joint advisory states that attackers used combinations of these and the newly listed flaws as entry vectors, underscoring that the campaign relied on a portfolio of vulnerable software rather than a single zero-day.

What this means for technologists, federal agencies, and affected enterprises

  • Technologists and security teams: Prioritize patching or removing the five newly listed CVEs from affected systems before October 11, 2026, and review the advisory’s described tactics — scanning, XSS, password spraying, VPN persistence, and scripted exfiltration — to detect similar behavior in logs and telemetry.
  • Federal agencies and policymakers: The KEV additions trigger a binding operational requirement — agencies must either apply fixes or discontinue impacted services by the October 11 deadline named by CISA.
  • Affected enterprises and procurement leaders: The advisory links exploitation to both off-the-shelf products (ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, ISC BIND) and to a vendor-associated campaign; organizations running these products should assess exposure and the feasibility of mitigation steps aligned with the KEV timeline.

The record published alongside the KEV update and the allied advisory leaves a clear short-term action: mitigate the five newly cataloged vulnerabilities and review systems for the described operational behaviors. With the October 11, 2026, compliance date set for federal agencies and a named list of exploited CVEs and techniques, defenders have an unambiguous checklist — and adversaries a plain set of targets they have already shown they can and will use.

Source: The Hacker News — Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies