Breaking
SecurityConfirmed

CISA Sets October 11 Patch Deadline

Five Flax Typhoon–exploited flaws join CISA's KEV catalog as federal agencies face an October 11, 2026, patch-or-discontinue deadline.

··3 hours ago·7 min read
a close up of a computer with green lights
Photo by Tyler on Unsplash

Five security flaws that a China-linked threat actor has already exploited are now on a federal remediation clock. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, and federal agencies have until October 11, 2026, to patch them or stop using the affected products.

The KEV additions coincide with a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. that warns about attacks enabled by a China-based cybersecurity company known as Integrity Technology Group. The same advisory links those operations to eight security vulnerabilities, including the five now in the catalog.

Five Flaws Under Active Exploitation

CISA's catalog now lists five vulnerabilities that the advisory says have been used in real attacks. Each carries its own severity score and its own exposure profile, and the range of affected products is broad.

  • CVE-2015-3306 (CVSS score: 10.0) — an improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
  • CVE-2021-3199 (CVSS score: 9.8) — a path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter, and could allow for remote code execution.
  • CVE-2023-22894 (CVSS score: 7.2) — a cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
  • CVE-2016-3081 (CVSS score: 8.1) — a command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
  • CVE-2015-5477 (CVSS score: 7.5) — a reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.

The five span file transfer, document collaboration, content management, web application frameworks, and DNS. That spread is central to why the advisory treats them as one campaign rather than five unrelated bugs.

Three Older Flaws Already Listed

The advisory's total of eight vulnerabilities is larger than the five new KEV entries. The remaining three were already in the catalog before this week's additions.

Those already-listed flaws are CVE-2014-6278, a GNU Bash operating system command injection vulnerability also known as Shellshock, added in October 2025; CVE-2019-11510, an Ivanti Pulse Connect Secure arbitrary file read vulnerability, added in November 2021; and CVE-2021-22205, a GitLab Community and Enterprise Edition remote code execution vulnerability, also added in November 2021.

The overlap means the advisory is not describing a purely new toolset. At least three of the flaws it names have been on the federal remediation list for years, while the five added Thursday are new to it.

How the Campaign Is Described

According to the joint advisory, the operations target the eight vulnerabilities to obtain initial access to organizations and siphon sensitive data. The described activity involves exploiting flaws using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers.

The advisory also describes persistence established through VPN software and exfiltration of emails and credentials using scripts. Those four elements — initial access, persistence, exfiltration, and the specific techniques used at each stage — are the tradecraft the advisory attributes to the campaign.

The five new KEV entries are the flaws CISA says have been abused in the wild. The catalog addition is what turns the advisory's technical detail into a deadline for federal agencies.

What CISA Says About the Targeting

The advisory's framing extends beyond the five flaws. A senior CISA official tied the activity to critical infrastructure and operational technology systems.

Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing.

— Chris Butera, Acting Executive Assistant Director for Cybersecurity

That statement is the advisory's description of the actors' positioning. It names critical infrastructure networks and OT systems as the environments in question, and it describes the aim as disrupting critical functions at a future time of the actors' choosing.

The Coalition Behind the Advisory

The joint advisory was released by Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. Seven countries signed onto the same document, which names both the vulnerabilities and the tradecraft in a single publication.

Alongside the advisory, CISA added the five flaws to the KEV catalog on Thursday. The timing ties the catalog update to the multi-country warning rather than treating them as separate events.

The advisory also identifies the activity as enabled by a China-based cybersecurity company known as Integrity Technology Group. That attribution appears in the same document that lists the eight exploited vulnerabilities.

The October 11 Deadline

In light of active exploitation, federal agencies are required to apply the necessary patches or discontinue their use by October 11, 2026. That is the remediation requirement the source states.

The requirement covers patching or discontinuing use. Those are the two options the source describes for federal agencies, and October 11, 2026, is the date attached to them.

The five vulnerabilities were added to the KEV catalog on Thursday. The catalog addition is what puts the flaws on the federal remediation timeline.

Where the Flaws Sit in the Stack

The affected products occupy different layers of a typical environment. ProFTPD handles file transfer. ONLYOFFICE Docs handles document collaboration. Strapi is a content management system. Apache Struts is a web application framework. ISC BIND provides DNS.

Each vulnerability has a distinct mechanism as described in the source. ProFTPD's flaw involves improper access control and the site cpfr and site cpto commands. ONLYOFFICE Docs' flaw involves a path traversal that occurs when JWT is used and a "/.." sequence in an image upload parameter. Strapi's flaw involves cleartext storage of sensitive information reachable through the query filter by an attacker with admin panel access. Apache Struts' flaw involves command injection via method:prefix when Dynamic Method Invocation is enabled. ISC BIND's flaw involves a reachable assertion triggerable through TKEY queries.

The CVSS scores range from 7.2 for the Strapi issue to 10.0 for the ProFTPD flaw. The ONLYOFFICE Docs flaw is scored 9.8, the Apache Struts flaw 8.1, and the ISC BIND flaw 7.5.

  • Five vulnerabilities added to the KEV catalog on Thursday.
  • Eight total vulnerabilities named in the joint advisory.
  • October 11, 2026, deadline for federal agencies to patch or discontinue use.
  • CVSS scores across the five new entries: 10.0, 9.8, 7.2, 8.1, and 7.5.

What the Advisory Says About Techniques

The advisory describes a specific set of techniques used to gain and hold access. Scanning tools are used to exploit flaws. Cross-site scripting attacks and password spraying on Microsoft Exchange servers are also described.

Persistence is set up through VPN software, according to the advisory. Exfiltration of emails and credentials is done using scripts.

Those techniques are attached to the same operations that target the eight vulnerabilities. The advisory presents them together as the activity's method, alongside the list of flaws.

Why the KEV Listing Matters to Federal Agencies

The KEV catalog is the mechanism CISA uses to flag vulnerabilities that have been exploited in the wild and require action from federal agencies. Adding five flaws at once, tied to a joint advisory from seven countries, puts those five on a defined timeline.

The October 11, 2026, date is the deadline federal agencies are required to meet. The source states the requirement as applying the necessary patches or discontinuing use — not one or the other exclusively.

For federal agencies running any of the five affected products, the practical question is whether the software is in use and whether it can be patched or removed by that date. The catalog listing and the advisory together identify the flaws and the tradecraft associated with them.

The advisory's statement about positioning within critical infrastructure networks, including OT systems, is the source's description of the actors' activity. It does not name specific victims or sectors.

What This Means Going Forward

The addition of five flaws to the KEV catalog, paired with a joint advisory from seven countries, suggests that the remediation window for these specific vulnerabilities is now defined by a federal deadline. For organizations outside the federal government, the same flaws remain in scope — the catalog is public, and the advisory names the products and the techniques.

The fact that three of the eight vulnerabilities in the advisory were already in the KEV catalog — some since 2021 — suggests the campaign draws on a mix of older and newer flaws rather than relying solely on the five added Thursday. That could mean defenders checking only against the newest entries would miss part of the picture described in the advisory.

For readers managing any of the affected products, the advisory's description of persistence through VPN software and exfiltration via scripts suggests that patching alone may not address every stage of the described activity. The source does not specify additional steps beyond patching or discontinuing use for federal agencies, but it does describe the techniques in full.

The October 11, 2026, deadline is the concrete date in the source. What happens after it — for federal agencies and for everyone else running the same software — is not described in the source material.

#cisa#kev#flax typhoon#vulnerabilities#cyber espionage

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories