CISA added CVE-2015-3306, the ProFTPD Improper Access Control Vulnerability, to its Known Exploited Vulnerabilities (KEV) catalogue on 8 October 2026. The vulnerability affects ProFTPD and could let remote attackers read and write arbitrary files using the `SITE CPFR` and `SITE CPTO` commands.
The flaw is an improper access control vulnerability. Its remote attack vector and potential for unauthorised file access and modification are reflected in a CVSS score of 10.0, rated Critical. The available data does not confirm whether a patch is available; no patch or advisory URL was provided. Organisations should consult the vendor information and cited security advisories for guidance.
KEV inclusion confirms that the vulnerability is being actively exploited. The data does not confirm use in ransomware campaigns. CISA set 11 October 2026 as the remediation deadline, giving affected organisations a short period to assess and address exposure.
CISA requires organisations to apply mitigations in accordance with vendor instructions and comply with its BOD 26-04 guidance on prioritising security updates, including the Forensics Triage Requirements. For cloud services, organisations should follow applicable BOD 26-04 guidance; if mitigations are unavailable, CISA says to discontinue use of the product. Stakeholders must evaluate each asset’s internet exposure and follow the applicable patching guidelines.
These requirements directly affect Federal Civilian Executive Branch (FCEB) agencies; all organisations should review their exposure and take appropriate action.
For full details, consult the [NVD entry for CVE-2015-3306](https://nvd.nist.gov/vuln/detail/CVE-2015-3306) and the [CISA KEV catalogue](https://www.cisa.gov/known-exploited-vulnerabilities-catalog).