THE article reports that on 8 October 2026 the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five high-risk vulnerabilities to its active threat list. These flaws are actively exploited in the wild and affect popular enterprise tools, including Apache Struts, Strapi, ONLYOFFICE, and ProFTPD. The piece emphasises that network defenders should apply vendor patches immediately to block remote takeovers.
Notable CVEs and exploitation status are presented as follows: CVE-2015-3306 (CVSS 10.0) in ProFTPD 1.3.5, used by attackers to read and write to arbitrary files; CVE-2021-3199 (CVSS 9.8), in Strapi up to 4.5.5, enabling sensitive data disclosure via the admin panel; CVE-2016-3081 (CVSS 8.1), associated with Apache Struts 2.3.x when Dynamic Method Invocation is enabled; CVE-2023-22894 (CVSS 7.5), in ONLYOFFICE Document Server before 5.6.3 affecting directory traversal; and CVE-2015-5477 (CVSS 7.5), in ISC BIND 9.x prior to certain patches causing remote denial of service.
The article notes that all five are “exploited” or actively used, with exploit evidence listed for several (including PoC availability via Metasploit/Nuclei).
For remediation, the piece provides concrete upgrade paths: Strapi to a version beyond 4.5.5, ONLYOFFICE Document Server to at least 5.6.3, Apache Struts 2.3 series to the latest secure releases, ISC BIND 9.x up to the newest point updates, and ProFTPD to version 1.3.5 with immediate system remediation. It stresses that absent mitigations from cloud providers, organisations should discontinue using the affected product to prevent exploitation.