CISA's Five Legacy Flaws Turn a Patch Order Into an Inventory Job

CISA added five flaws to its Known Exploited Vulnerabilities catalog on 8 October 2026 with an 11 October deadline, and every one of them lives in self-hosted server software.

CISA's Known Exploited Vulnerabilities catalog page showing the ProFTPD entry added on 8 October 2026, beside a Netics editorial card listing the five self-hosted services on the list.
CISA's Known Exploited Vulnerabilities catalog page beside the Netics editorial summary of the five flaws added on 8 October 2026, the 11 October deadline and the four forwarding-triage flags that came with them.

TL;DR

  • The Known Exploited Vulnerabilities catalog is a CISA list of flaws that attackers have already used in the wild, with a remediation date attached for US federal agencies.
  • On 8 October 2026 CISA added five flaws to that catalog, and each one carries an 11 October deadline plus a vendor fix that has existed for years in most cases.
  • Every one of the five lives in software a company runs on its own servers: an ISC BIND name server, a ProFTPD FTP server, an Apache Struts web framework, an ONLYOFFICE Documents server and a Strapi content system.
  • The listed impact runs from a remote denial of service in BIND through unauthenticated file read and write in ProFTPD to command injection in Struts and path traversal reaching code execution in ONLYOFFICE.
  • Four of the five entries also carry CISA's forensic-triage flag, which asks for a compromise check on top of the upgrade work.
  • The same day, the FBI, CISA and the NSA published joint advisory AA26-281A on a China-based company enabling actors that scan at scale, and the Justice Department announced the seizure of seven domains carrying a scanner and a delivery tool.
  • An inventory pass answers the first question a patch list raises, which is whether the service exists anywhere in your estate, and the answer decides how much of the October list applies to you.
  • The detection signals differ per product, so the log search that follows a finding is specific: file-transfer commands in ProFTPD, a method prefix in Struts, an odd upload path in ONLYOFFICE and query filters in Strapi.

What CISA added on 8 October

The catalog works as a deadline engine. Each entry names a flaw, the products it affects, the date it was added and the date by which federal agencies either apply mitigations or stop using the product, and every entry in this batch is marked for forensic triage or left as unknown on the ransomware question.

The ProFTPD entry is the clearest example of the pattern. "ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands," the catalog states, classifies it under CWE-284, and records the addition on 8 October 2026 with a due date of 11 October 2026. Two published commands in a file-transfer server produce arbitrary file access, and the fix has been available since 2015.

Capture of CISA's Known Exploited Vulnerabilities catalog page on cisa.gov, showing the CVE-2015-3306 ProFTPD entry.
Capture of CISA's own Known Exploited Vulnerabilities catalog page (cisa.gov, retrieved 9 October 2026): the CVE-2015-3306 entry as published, with the site cpfr and site cpto description, CWE-284, the 8 October addition and the 11 October due date.

That age is the story. Suriq's analysis put the batch in one line: "The news here is not a fresh zero-day." Four of the five flaws were disclosed between 2015 and 2021, and CISA still attached a three-day window to them, which is the behaviour of an agency reacting to exploitation happening now.

The five services and what each flaw gives an attacker

Read as a group, the five flaws describe the shape of a typical mid-size server estate: the resolver, the file-transfer box, the Java application server, the document collaboration service and the CMS. Suriq listed them in one sentence as "a DNS daemon, an FTP server, a web framework, a document server, and a headless content system."

The severities, as recorded in the KEV reporting, run from 10.0 for the ProFTPD file read and write through 9.8 for the ONLYOFFICE Docs path traversal, 8.1 for the Apache Struts command injection, 7.5 for the BIND denial of service and 7.2 for the Strapi cleartext exposure. Two of the five are internet-facing by design in most deployments, and the DNS resolver is often the piece nobody lists in an asset inventory.

The Apache Struts entry carries the same qualifier the original disclosure did: the command injection works through the method prefix when Dynamic Method Invocation is enabled, which means the flaw's reach depends on a configuration choice made years ago. Strapi's flaw needs admin-panel access to filter on private fields, and CISA notes the affected builds may be end-of-life, which removes patching as an option for those instances.

The joint advisory behind the listing

Catalog additions usually arrive alone. These five arrived with a broader document, and the document explains why old flaws came back onto a deadline.

Joint advisory AA26-281A describes the actors as "Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group," who "are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors." Scanning is the first verb in that sentence, and scanning is what turns an unmaintained service into an incident.

Netics editorial card on the five flaws CISA added on 8 October 2026, with the deadline and the forensic-triage flag the catalog attaches to four of them.
Netics editorial card built from CISA's Known Exploited Vulnerabilities catalog: the three-day window between the 8 October addition and the 11 October due date, and the forensic-triage flag carried by four of the five entries.

The advisory's technique list adds detail worth reading twice: cross-site scripting attacks and password spraying against Microsoft Exchange servers, persistence through VPN software, and exfiltration of emails and credentials through scripts. Its recommended mitigations are the ordinary ones stated plainly, asking organizations to prioritize disabling unused services and ports, sanitizing web application inputs, implementing multifactor authentication for all services, and applying timely patches.

Suriq's reporting ties the two documents together and adds the enforcement side: the same day, the Department of Justice announced the seizure of seven domains, running "a Python scanner called MicroScan and a malware delivery system called FishHub." The scanner reportedly "carries more than 1,300 penetration-testing scripts, including checks for flaws as old as the 2014 Shellshock bug."

How an inventory finds what a patch list assumes

A patch list assumes you know where the software runs. Nothing in the October batch confirms that assumption, and the age of the flaws is the reason: a BIND resolver installed with a distribution in 2016 sits in a configuration management record that stopped being updated when the service started working.

The practical order follows from that. Enumerate what answers on your internet-facing addresses, then match the results against the five products, including the versions hiding inside appliances. Fetch the fixed release for each hit: BIND 9.9.7-P2 or 9.10.2-P3 and later, ProFTPD 1.3.5a or mod_copy disabled, Apache Struts 2.3.20.3, 2.3.24.3 or 2.3.28.1, ONLYOFFICE 5.6.3 or later, and Strapi 4.8.0 or later, with the warning that the affected Strapi builds may be end-of-life and belong on a retirement list.

Anything that cannot be upgraded inside the window comes off the public internet or goes behind authentication, and the entries ask for something more than a version check. Four of the five carry the forensic-triage flag, which is the instruction to look for evidence of use before closing the ticket: unexpected files, new accounts, web shells and outbound connections.

What to do before 11 October

The work splits into three passes that fit inside the window. The first is exposure: identify which of the five services accept connections from outside your network, and count the DNS resolvers and file-transfer hosts that answer to the internet rather than the ones on a diagram.

Capture of CISA's joint advisory AA26-281A page on cisa.gov, describing the scanning and exploitation activity behind the October listings.
Capture of CISA's own joint advisory AA26-281A page, "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data" (cisa.gov, published 8 October 2026, retrieved 9 October 2026): the advisory's affected-product list and executive summary.

The second pass is removal. Where a service exists for a workflow nobody uses, retiring it clears the finding and the maintenance obligation at once, and an FTP server is the easiest candidate for that treatment. Where the service is load-bearing, the upgrade path above applies in the order that keeps the service answering.

The third pass is the log read, and it differs by product. ProFTPD leaves the site cpfr and site cpto commands in its own log. Struts shows a method prefix on an .action request. ONLYOFFICE records the upload parameter with a traversal sequence. Strapi shows the odd query filter. The BIND denial of service leaves almost nothing, which is why the signal to alert on is the named process dying and restarting. Where credentials or tokens passed through an exposed instance, rotation follows the investigation, and the Strapi guidance asks for admin credentials and password-reset tokens to be reset after the upgrade.

That sequence is the same discipline behind the security audits we run for small companies, where an inventory and an upgrade path matter more than a scanner report, and it is the reason an existence question gets answered before a patch question.

The part that outlasts this batch of CVEs

The October batch will close and the next one will arrive with the same shape, because the mechanism behind it does not change with the CVE number. An industrialised scanner finds unmaintained software, and unmaintained software accumulates in exactly the places an organisation stops looking: the resolver, the transfer host, the application server nobody redeployed after the project went live.

Two habits shorten the next round. Keep a current list of what answers on your public addresses, with an owner and a review date per service, because the finding that costs a week is the service missing from the list. Treat end-of-life software as a scheduled retirement rather than a patch backlog item, since a build with no supported release cannot be fixed in a window.

Netics editorial checklist of the five CVEs added to CISA's catalog on 8 October 2026 with the service and the fixed release for each.
Netics editorial card built from CISA's KEV entries and the published fix versions: the five CVEs from the 8 October 2026 addition with the service each one affects and the release that closes it.

The five flaws from 8 October are ordinary in themselves. What makes them worth acting on is the evidence CISA published alongside them: a scanner carrying more than 1,300 exploit scripts, a batch of three-day deadlines on flaws from 2015, and a public list that names the exact services to look for. An inventory closes that gap at Netics, and it closes it faster than a patch cycle planned around a version list you cannot trust.

Sources

Source: Known Exploited Vulnerabilities Catalog — cisa.gov/known-exploited-vulnerabilities-catalog, CISA, entries added 8 October 2026, retrieved 2026-10-09 (the CVE-2015-3306 ProFTPD entry describing an improper access control vulnerability allowing remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands, its CWE-284 classification, its 8 October 2026 addition and 11 October 2026 due date, the unknown ransomware association, and the forensic-triage requirement with the BOD 26-04 action line).

Source: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, advisory AA26-281A — cisa.gov/news-events/cybersecurity-advisories/aa26-281a, CISA, published 8 October 2026, retrieved 2026-10-09 (the description of the actors enabled by the Integrity Technology Group combining automated scanning tools, large-scale botnets and hands-on exploitation against organizations worldwide including US critical infrastructure sectors, the use of scanning tools, cross-site scripting attacks and password spraying on Microsoft Exchange servers, persistence through VPN software, exfiltration of emails and credentials using scripts, the affected product list, and the recommended mitigations covering unused services and ports, input sanitization, multifactor authentication and timely patches).

Source: CISA KEV: Five Old Server Bugs Exploited at Scale — suriq.io/blog/flax-typhoon-legacy-server-bugs-cisa-kev, Suriq, published 9 October 2026, retrieved 2026-10-09 (the identification of the five 8 October flaws as CVE-2015-5477 in ISC BIND, CVE-2015-3306 in ProFTPD, CVE-2016-3081 in Apache Struts, CVE-2021-3199 in ONLYOFFICE Docs and CVE-2023-22894 in Strapi, the characterization of the affected software as a DNS daemon, an FTP server, a web framework, a document server and a headless content system, the 11 October federal deadline, the disclosure dates between 2015 and 2021, the per-flaw mechanics including the TKEY query, the mod_copy SITE CPFR and SITE CPTO commands, Dynamic Method Invocation in Struts, the ONLYOFFICE image-upload traversal under JWT and the Strapi query filter with end-of-life builds, the joint FBI, CISA and NSA advisory and the seizure of seven domains running a Python scanner called MicroScan and a malware delivery system called FishHub, the more than 1,300 penetration-testing scripts including checks for flaws as old as the 2014 Shellshock bug, and the per-product log observables with named dying and restarting as the BIND signal).

Source: This Week in CISA KEV: 6 Exploited Flaws — datawater.com/cisa-kev-china-linked-legacy-vulnerabilities/, DataWater, published 9 October 2026, retrieved 2026-10-09 (the six CVEs added between 3 and 9 October 2026, the FBI-led joint advisory on Integrity Technology Group, the fixed releases for BIND, Apache Struts, Strapi, ONLYOFFICE and ProFTPD, the instruction to reset admin credentials and password-reset tokens on exposed Strapi instances, and the note that the affected Strapi versions may be end-of-life).

Source: CISA Sets October 11 Patch Deadline — xploitwire.com/article/cisa-sets-october-11-patch-deadline, Xploitwire, published 9 October 2026, retrieved 2026-10-09 (the CVSS scores across the five new entries of 10.0, 9.8, 7.2, 8.1 and 7.5, the eight vulnerabilities named in the joint advisory, and the 11 October 2026 requirement for federal agencies to patch or discontinue use).

Source: CISA's Known Exploited Vulnerabilities catalog and joint advisory AA26-281A — cisa.gov, 8 October 2026; Suriq's analysis — suriq.io, 9 October 2026; DataWater's KEV round-up — datawater.com, 9 October 2026; Xploitwire's report — xploitwire.com, 9 October 2026. All retrieved 2026-10-09. Figures: two captures of CISA's own published pages, plus two Netics editorial diagrams rendered from the same sources.