CISA KEV Alert 8 Oct 2026, 19:03 UTC

CISA Flags Actively Exploited ONLYOFFICE Flaw That Could Enable Remote Code Execution

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2021-3199 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 October 2026. The vulnerability affects ONLYOFFICE Docs and is a path traversal flaw in ONLYOFFICE Docs Server that could allow remote code execution.

The flaw can occur when JWT is used: a `/..` sequence in an image upload parameter can enable path traversal and potentially remote code execution. The vulnerability has a CVSS score of 9.8, rated Critical. The supplied data does not confirm whether a patch is available; it lists patch status as unknown. CISA’s notes link to a vendor changelog, but no patch or advisory URL is provided.

CISA’s KEV listing confirms that the vulnerability is being actively exploited. Use in ransomware campaigns is unknown. Federal Civilian Executive Branch (FCEB) agencies must meet CISA’s remediation deadline of 11 October 2026.

CISA requires organisations to apply mitigations in accordance with vendor instructions and relevant BOD 26-04 guidance, including its Forensics Triage Requirements. Where mitigations are unavailable, organisations should discontinue use of the product. Stakeholders must evaluate each asset’s internet exposure and follow applicable BOD 26-04 patching guidance. FCEB agencies are directly subject to CISA’s remediation requirement; all organisations should review their exposure and take appropriate action.

For full details, see the [NVD entry](https://nvd.nist.gov/vuln/detail/CVE-2021-3199) and the [CISA KEV catalogue](https://www.cisa.gov/known-exploited-vulnerabilities-catalog).

View CISA KEV Entry

Article by CyberSIXT