The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five serious vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following their exploitation by a threat actor known as Flax Typhoon, linked to Chinese interests. Federal agencies now face a deadline of October 11, 2026 to patch these flaws or stop using affected systems. The newly listed vulnerabilities span file transfer protocols, content management systems, and DNS software.
What vulnerabilities are affected?
The five flaws recently added to KEV are:
- CVE-2015-3306 – A severity 10.0 issue in ProFTPD. Attackers can abuse “site cpfr” and “site cpto” commands to read from or write to arbitrary files.
- CVE-2021-3199 – A 9.8 severity vulnerability in ONLYOFFICE Docs that allows path traversal through a crafted JWT in an image upload, risking remote code execution.
- CVE-2023-22894 – A severity 7.2 flaw in Strapi that lets an attacker with access to its admin panel use the query filter feature to pull sensitive user data stored in cleartext.
- CVE-2016-3081 – An 8.1-severity command injection flaw in Apache Struts that permits remote code execution when Dynamic Method Invocation is enabled via the method:prefix configuration.
- CVE-2015-5477 – A 7.5-severity reachable assertion vulnerability in ISC BIND, exploitable via TKEY queries to cause denial of service.
Who is Flax Typhoon and what are they up to?
Flax Typhoon is a China-linked threat actor identified as exploiting multiple software flaws—including these five—to penetrate networks, access sensitive data, and establish persistence in victim systems. Tactics observed include using scanning tools, cross-site scripting, password spraying against Microsoft Exchange servers, and exfiltrating credentials and emails. Persistence is achieved by abusing VPN software.
The U.S., along with allies including Australia, Canada, Japan, New Zealand, Spain, and the U.K., issued a joint advisory warning that a China-based cyber firm known as Integrity Technology Group is connected to these operations. In some cases, three other vulnerabilities exploited by the adversary were already part of the KEV catalog.
CISA’s deadline & what it means for federal agencies
Because these vulnerabilities are now officially listed in the KEV catalog, U.S. federal entities are required to remediate the risks—either by patching or disabling affected systems—by October 11, 2026.
Failure to comply could leave agencies exposed to data leaks, service outages, or worse—active breach campaigns by Flax Typhoon or similarly motivated threat actors. The addition to the KEV roster is one of several recent moves by CISA to tighten security expectations across government systems.
These vulnerabilities are part of a broader set of eight flaws used by Flax Typhoon in its campaigns. Before today, three of those were already covered in KEV: CVE-2014-6278 (Shellshock), CVE-2019-11510 (Ivanti Pulse Connect Secure arbitrary file read), and CVE-2021-22205 (GitLab remote code execution).
Bottom line: The newly listed flaws present immediate risk. With the October 11 deadline fast approaching, agencies must act quickly to patch systems or disable vulnerable services.
Why it matters: This episode underscores the urgency of maintaining updated patches across critical infrastructure software. A single exposed vulnerability can be all an advanced actor needs to infiltrate government networks. With adversaries like Flax Typhoon pairing exploitative campaigns with geopolitical backing, the stakes aren’t just technical—they’re national.