CISA adds five flaws to Known Exploited Vulnerabilities catalog
CISA added flaws in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND to its Known Exploited Vulnerabilities catalog. The flaws are tied to cyber operations attributed to China-linked Integrity Technology Group; U.S. federal agencies must fix them by October 11, 2026.
- CVE-2015-3306 in ProFTPD carries a CVSS score of 10.0
- CVE-2021-3199 in ONLYOFFICE Docs is 9.8, CVE-2016-3081 in Apache Struts is 8.1
- The U.S. seized tools Microscan and FishHub linked to Integrity Tech
- FCEB agencies must remediate by October 11, 2026
Read next
Security