CISA: Five Flax Typhoon CVEs Added, Feds Have Until Oct 11
CISA added five vulnerabilities tied to China's Flax Typhoon to its KEV catalog on Oct 8; federal agencies must patch or discontinue use by October 11.

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on October 8, citing active exploitation by Flax Typhoon, a Chinese state-sponsored group linked to Beijing contractor Integrity Technology Group. Federal civilian executive branch agencies have until October 11 to patch or discontinue affected products under BOD 26-04.
All five carry the same remediation deadline. Here is what is on the list:
| CVE | Product | CVSS | Vulnerability Class |
|---|---|---|---|
| CVE-2015-3306 | ProFTPD | 10.0 | Improper access control |
| CVE-2021-3199 | ONLYOFFICE Docs | 9.8 | Path traversal / RCE chain |
| CVE-2016-3081 | Apache Struts | 8.1 | Command injection via DMI |
| CVE-2015-5477 | ISC BIND | 7.8 | DoS via TKEY queries |
| CVE-2023-22894 | Strapi | 4.9 | Cleartext credential exposure |
These are not new vulnerabilities. The oldest dates to 2015. What is new is confirmed, active exploitation at scale by a Chinese APT that the FBI disrupted earlier this week. The additions follow a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK, and the U.S. documenting Flax Typhoon’s use of scanning tools, cross-site scripting attacks, and password spraying against Microsoft Exchange servers, with persistence maintained through VPN software.
What to actually patch first
Start with CVE-2015-3306. ProFTPD’s CVSS 10.0 improper access control flaw lets remote attackers read and write arbitrary files via the SITE CPFR and SITE CPTO commands. A patch has been available since 2015. Upgrade to ProFTPD 1.3.5 or later.
ONLYOFFICE Docs users should check CVE-2021-3199: the path traversal in image upload parameters can chain into remote code execution when JWT is in use. Check your ONLYOFFICE version against the vendor’s fix.
For Apache Struts, CVE-2016-3081 requires Dynamic Method Invocation to be enabled to trigger command injection via the method: prefix. Disable DMI if you have not already and upgrade past the vulnerable range.
CVE-2015-5477 in ISC BIND crashes named via crafted TKEY queries. BIND 9.10.2-P3 or later resolves it. If you are still running unpatched BIND on a public-facing resolver, this is a straightforward denial-of-service exposure.
Strapi’s CVE-2023-22894 is the lowest CVSS of the batch at 4.9, but it exposes sensitive user details through the admin panel’s query filter. CISA notes it may affect end-of-life versions and can chain with CVE-2023-22621 for RCE. Strapi’s advisory recommends upgrading to a supported version.
Non-federal context
The October 11 deadline is legally binding only for FCEB agencies. That said, these flaws are being actively weaponized by a nation-state actor with a documented interest in critical infrastructure. If you operate ProFTPD, ONLYOFFICE, an Apache Struts app, BIND, or a Strapi instance, the federal deadline is a useful forcing function regardless of your sector.
Sources: CISA KEV catalog, The Hacker News reporting on the KEV additions, CISA BOD 26-04.
Related: CISA Adds Seven Flaws Tied to Reverse Shells and Miners, CISA KEV: Cisco, Citrix, Fortinet in September Batch, What Is the CISA KEV Catalog.
- [ CRITICAL ]CVE-2015-3306ProFTPD Improper Access Control Vulnerability
- [ CRITICAL ]CVE-2021-3199ONLYOFFICE Docs Server Path Traversal Vulnerability
- [ HIGH ]CVE-2016-3081Apache Struts Command Injection Vulnerability
- [ HIGH ]CVE-2015-5477 ISC BIND Data Processing Errors Vulnerability
- [ MEDIUM ]CVE-2023-22894Strapi Cleartext Storage of Sensitive Information Vulnerability
Found this useful? Share it.


