Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Overcast Clouds Humidity: 90%
Wind: 5.14 M/S

CISA Orders Federal Agencies to Patch Five Flax Typhoon-Linked Vulnerabilities by October 11

CISA Orders Federal Agencies to Patch Five Flax Typhoon-Linked Vulnerabilities by October 11

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five newly identified security vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that they have been actively leveraged by the China-linked cyber espionage group Flax Typhoon. The move highlights ongoing concerns about state-sponsored cyber operations targeting vulnerable systems to gain unauthorized access, establish persistence, and steal sensitive information.

The newly added vulnerabilities span several widely used enterprise technologies and software platforms:

  • CVE-2015-3306 (CVSS 10.0) – A critical access control flaw in ProFTPD that allows remote attackers to read from and write to arbitrary files through misuse of the site cpfr and site cpto commands.
  • CVE-2021-3199 (CVSS 9.8) – A severe path traversal vulnerability affecting ONLYOFFICE Docs when JSON Web Token (JWT) functionality is enabled. Attackers can exploit the flaw through crafted image-upload requests, potentially leading to remote code execution.
  • CVE-2023-22894 (CVSS 7.2) – A vulnerability in Strapi involving the insecure storage of sensitive information, allowing attackers with administrative access to expose confidential user data through query filtering mechanisms.
  • CVE-2016-3081 (CVSS 8.1) – A command injection flaw impacting Apache Struts that can enable arbitrary code execution when Dynamic Method Invocation is enabled and malicious input is supplied through the method:prefix parameter.
  • CVE-2015-5477 (CVSS 7.5) – A denial-of-service vulnerability in ISC BIND, where specially crafted TKEY requests can trigger a reachable assertion failure and disrupt DNS services.

Linked to China-Based Cyber Operations

The KEV additions coincide with a joint cybersecurity advisory issued by authorities from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States, detailing cyber activity associated with the China-based technology and cybersecurity firm Integrity Technology Group.

According to the advisory, threat actors connected to these operations have been exploiting a total of eight known vulnerabilities to gain initial access to targeted networks, conduct espionage activities, and exfiltrate sensitive organizational data. The attacks reportedly combine vulnerability scanning, exploitation of web application weaknesses, cross-site scripting (XSS) techniques, and password-spraying campaigns directed at Microsoft Exchange environments.

Once inside a network, attackers have been observed deploying persistence mechanisms through VPN infrastructure, harvesting credentials, and using custom scripts to extract emails and other sensitive information from compromised systems.

Additional Exploited Vulnerabilities Already in the KEV Catalog

The joint advisory also references three previously known vulnerabilities that had already been added to CISA's KEV catalog:

  • CVE-2014-6278 (Shellshock) – A command injection vulnerability affecting GNU Bash.
  • CVE-2019-11510 – An arbitrary file-read vulnerability in Ivanti Pulse Connect Secure.
  • CVE-2021-22205 – A remote code execution vulnerability affecting GitLab Community and Enterprise Editions.

Together with the five newly added flaws, these vulnerabilities form part of the attack toolkit observed in Flax Typhoon intrusion campaigns.

Ongoing Threat to Critical Infrastructure

CISA officials warned that Chinese state-linked cyber actors continue to position themselves within critical infrastructure networks, including operational technology (OT) environments. Security agencies assess that these intrusions may be intended to provide strategic access that could be used to disrupt critical services during future geopolitical conflicts or crises.

The activity underscores continued concerns around pre-positioning operations, where threat actors establish long-term footholds inside critical systems while remaining dormant until activation is deemed necessary.

Federal Agencies Face October 11 Deadline

Due to confirmed active exploitation, CISA has directed all Federal Civilian Executive Branch (FCEB) agencies to remediate the affected vulnerabilities or remove vulnerable products from operation no later than October 11, 2026.

Organizations beyond the federal government are also strongly encouraged to review their environments, identify exposed systems, apply available security updates, and monitor for indicators of compromise associated with Flax Typhoon activity. Rapid remediation is particularly important given the demonstrated ability of threat actors to leverage these vulnerabilities for network infiltration, persistence, credential theft, and data exfiltration.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.