THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3306 in ProFTPD; CVE-2021-3199 in ONLYOFFICE Docs when JWT is enabled; CVE-2023-22894 in Strapi; CVE-2016-3081 in Apache Struts; and CVE-2015-5477 in ISC BIND.
CISA notes these as high‑risk issues that have been observed in real-world exploitation, and they have been incorporated into a broader advisory connected to China‑linked activity tied to Integrity Technology Group. The entry for each CVE includes its CVSS context: ProFTPD (10.0), ONLYOFFICE Docs (9.8), Strapi (7.2), Apache Struts (8.1), and BIND (7.5).
The article describes the wider operation as part of a joint governmental advisory by seven countries and the U.S., linked to Integrity Tech tools and campaigns that sought initial access and data exfiltration across organisations, including critical infrastructure. It cites exploitation methods such as large‑scale vulnerability scanning, cross‑site scripting, password spraying against Microsoft Exchange, VPN usage for persistence, and scripts to harvest emails and credentials.
Federal guidance under Binding Operational Directive 22‑01 requires agencies to address the KEV flaws by the due date, with a reminder for private organisations to assess their own networks against the KEV catalog. The report also references seizures of Integrity Tech tools Microscan and FishHub, described as used in related cyber espionage activities. 11 October 2026