thehackernews.com 9 Oct 2026, 12:21 UTC

CISA Adds Five Flaws to KEV After Flax Typhoon Attacks

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after reports that a China-linked actor group, Flax Typhoon, abused them in targeted intrusions. The flaws are: CVE-2015-3306 (ProFTPD) with a CVSS of 10.0, CVE-2021-3199 (ONLYOFFICE Docs) with a CVSS of 9.8, CVE-2023-22894 (Strapi) with a CVSS of 7.2, CVE-2016-3081 (Apache Struts) with a CVSS of 8.1, and CVE-2015-5477 (ISC BIND) with a CVSS of 7.5.

The addition aligns with a joint international advisory warning of attacks attributed to Integrity Technology Group, a China-based cybersecurity company.

The article notes that eight security vulnerabilities were used to gain initial access, with Flax Typhoon employing scanning tools, cross-site scripting, and password spraying on Microsoft Exchange servers, followed by establishing persistence via VPN software and exfiltrating emails and credentials through scripts. Three other KEV-listed flaws from prior years—CVE-2014-6278 (Shellshock), CVE-2019-11510 (Ivanti Pulse Connect Secure), and CVE-2021-22205 (GitLab RCE)—are also within the KEV catalogue.

Federal agencies are being urged to patch or discontinue affected technologies by 11 October 2026. Acting statements from CISA emphasise the ongoing risk of China-linked actors targeting critical infrastructure, underscoring the need for rapid remediation where these flaws are present.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline