CISA Adds Five Old CVEs to KEV as FBI Seizes Flax Typhoon's Scanning Tools
CISA's 8 October KEV batch is five CVEs from 2015 to 2023, all tied to a China-linked scanning operation whose FishHub and MicroScan tools the FBI just seized.
What Happened
On 8 October 2026 CISA pushed catalog version 2026.10.08 of the Known Exploited Vulnerabilities list with five new entries. None of them is new. The oldest two were published in 2015, the newest in 2023, and every one of them has had a vendor fix for years:
- **CVE-2015-3306**, ProFTPD improper access control. The mod_copy module in ProFTPD 1.3.5 lets an unauthenticated client read and write arbitrary files through the `site cpfr` and `site cpto` commands. NVD scores it CVSS 3.1 10.0 with changed scope.
- **CVE-2015-5477**, ISC BIND data processing error. A crafted TKEY query trips a REQUIRE assertion in `named`, which exits. Affects 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3. CVSS 7.5, availability only.
- **CVE-2016-3081**, Apache Struts command injectionCommand Injectionπ‘οΈA security vulnerability that allows attackers to execute arbitrary operating system commands on the host system through a vulnerable application.. With Dynamic Method Invocation enabled, the `method:` prefix evaluates chained expressions and executes code. Affected ranges are 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1 and 2.3.25 to 2.3.28. CVSS 3.0 8.1 because attack complexity is rated high.
- **CVE-2021-3199**, ONLYOFFICE Docs path traversalPath Traversalπ‘οΈA web vulnerability (CWE-22) where user-supplied input in a file path escapes the directory the application intended to serve from, typically via parent-directory references, letting an attacker read or write files elsewhere on the server.. A `/..` sequence in an image-upload parameter to `/upload` in Document Server before 5.6.3, when JWT is enabled, reaches remote code execution. CVSS 9.8.
- **CVE-2023-22894**, Strapi cleartext storage of sensitive information. An attacker who already has admin-panel access abuses the query filter to pull user details, including password hashes and reset tokens. NVD carries two scores, 4.9 from the primary assessment and 7.2 from a secondary one. CISA's announcement and most reporting quote 7.2.
All five carry a due date of 11 October 2026 under BOD 26-04BOD 26-04π‘οΈCISA Binding Operational Directive 26-04, issued 10 June 2026, which replaced BOD 22-01. It assigns federal civilian agencies remediation deadlines of 3, 14, or 60 days based on asset exposure, KEV status, exploit automation, and post-exploitation impact, and requires forensic triage for the 3-day tier., the standard three-day window CISA now applies to entries it considers urgent.
The additions were not a routine catalogue update. They landed alongside two other actions the same day. The FBI, CISA and NSA published joint advisory AA26-281A, co-sealed by the UK NCSC, Australia's ACSC, the Canadian Centre for Cyber Security, Japan's NPA and NCO, New Zealand's NCSC and Spain's CNI. It describes a China-based contractor, Integrity Technology Group, supplying scanning infrastructure and hands-on exploitation tooling to actors whose tradecraft matches the clusters tracked as Flax Typhoon, Ethereal Panda and Red Juliett. And the Department of Justice announced that the FBI, under warrants from the Western District of Pennsylvania, had seized domains used to operate two of Integrity Tech's tools: MicroScan, a vulnerabilityVulnerabilityπ‘οΈA weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm. scanner reached at c0cc[.]cc, and FishHub, a spear-phishingPhishingπ‘οΈA social engineering attack using fake emails or websites to steal login credentials or personal info. platform delivered through 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. BleepingComputer and Help Net Security list a seventh seized domain, 98aiblog[.]com, used to host SoftEther VPN access.
Who Is Affected
The advisory lists eight CVEs the actors successfully exploited. The five above are the new KEV entries. The other three were already catalogued: CVE-2014-6278 (GNU Bash, Shellshock, through 4.3 bash43-026), CVE-2019-11510 (Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, 9.0 before 9.0R3.4) and CVE-2021-22205 (GitLab, all versions from 11.9 in the affected range).
The pattern matters more than the individual products. These are FTP daemons, authoritative DNS servers, a Java web framework, a document server that ships embedded in collaboration suites, a headless CMSHeadless CMSπ‘οΈA content management system that stores and serves content through an API with no built-in front end, leaving presentation to a separate application. Strapi is a widely used example., a shell, an SSL VPN and a Git platform. Several of them typically run on appliances or vendor images where the operator never sees a version string. The advisory's victim list reflects that spread: US Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology, plus law enforcement, education and religious organisations, with further victims across Southeast Asia, Africa and North America. Activity dates back to at least mid-January 2021, and some of the 39 pages of indicators go back to 2016.
The DOJ filing adds names. MicroScan was used to scan a power company in South Carolina, a multinational NGO, airports in Japan and Poland, and natural gas and electricity providers in Taiwan. Two Taiwanese universities were breached after being scanned, in August 2022 and March 2023. DOJ puts FishHub's victims at roughly 20 Taiwanese universities. BleepingComputer, citing data recovered from the FishHub server, says six. Both figures are reported here because the primary and secondary sources disagree.
Technical Analysis
The advisory describes a pipeline rather than a single intrusion technique. Reconnaissance runs on a botnetBotnetπ‘οΈA network of internet-connected devices compromised and controlled by an operator, used for denial-of-service attacks, proxying malicious traffic, credential stuffing or spam. Edge routers are prized botnet hosts because they are numerous, always on, directly reachable and rarely inspected by their owners. of consumer devices infected with a Mirai variant, the same class of infrastructure the FBI dismantled as Raptor Train in September 2024, when it controlled more than 200,000 devices. The botnet sweeps six ports: 21, 22, 53, 80, 443 and 1080. Hosts that answer are handed to MicroScan, a Python web application holding more than 1,300 penetration-testing scripts, in use since 2017, with modules for OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. Alongside it the operators run commodity tooling: Nmap, masscan, WPScan, BBScan, dirsearch, Fscan, ksubdomain, OneForAll and ShuiZe. How this stage works, and why it keeps finding 2015 bugs, is the subject of How a Contractor's Scanning Platform Turns a Botnet Into a Target List.
The exploitExploitπ‘οΈCode or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access. stage is what the KEV additions describe. Each of the five is a one-request compromise against a service that answers on one of those six ports. The BIND entry looks out of place in an espionage toolkit, since it only crashes `named`, but port 53 is on the scan list and a DNS outage is a useful lever during an intrusion. The Strapi bug is the other outlier: it needs admin-panel access first, which means it is a post-authentication step, probably after password reuse or a stolen session, not an initial-access vector.
Two more initial-access routes do not involve a CVE. Cross-site scripting payloads present a fake username and password prompt and offer a password-protected ZIP that drops `live700_v1.exe`, which spawns a `DiagTrack.exe` process and beacons to dns.studiocloud[.]xyz. And EBurst, an open-source Python tool, sprays passwords at every Exchange surface it can reach: ECP, EWS, OAB, OWA, RPC, MAPI, PowerShell, AutodiscoverAutodiscoverπA Microsoft service that automatically configures email client settings by querying DNS records to locate the Exchange server. and ActiveSync.
After access, the toolset is deliberately ordinary. Web shells named b374.php, back.pl, error.jsp, file_back.aspx, gf.phtml and yaml-payload.jar. SoftEther VPN installed as `conhost.exe` or `dllhost.exe` and configured to reconnect at startup, giving the operators a tunnel that survives reboots. `DC.exe` runs DCSyncDCSyncπ‘οΈA credential-theft technique in which an attacker impersonates a domain controller and asks a real one to replicate account data, including password hashes, over the normal Active Directory replication protocol. against Active Directory to pull credential material by asking a domain controller to replicate. A PHP script, `curlc4.txt`, drives the Exchange Web Services API to collect mail, stages archives at paths such as `/var/tmp/.sess.zip`, encrypts them with RC4 and AES-128-CBC, and talks to natcloudservice[.]com. A Linux tool, `office-cli`, does the same against Microsoft 365Microsoft 365πMicrosoft's subscription-based cloud productivity suite including Office applications, Exchange Online, SharePoint, and Teams. using a client ID, tenant ID and secret stored in JSON. The stolen mail then surfaces in a web application that lets third parties browse it by adjusting URL arguments, with access in some cases restricted to IP addresses in Xiamen. The detection side of this is covered in How to Spot DCSync and Mailbox Harvesting After a Web Server Is Breached.
Immediate Actions
**Treat the deadline as a search, not a patch.** For federal agencies the five CVEs must be remediated by 11 October. For everyone else the useful exercise is proving absence. ProFTPD 1.3.5 with mod_copy, BIND below 9.9.7-P2 or 9.10.2-P3, Struts 2.3.x in the listed ranges with Dynamic Method Invocation on, Document Server below 5.6.3 and Strapi at 4.5.5 or earlier are the targets. For Strapi, note that NVD's affected-configuration data runs to versions before 4.8.0 while the advisory says up to 4.5.5, so verify against your installed build rather than either range. The patched Struts release number does not appear in the sources fetched for this article, so confirm it against the Apache S2-032 advisory before closing a ticket.
**Look for the services, not the CVEs.** Anything answering on 21, 22, 53, 80, 443 or 1080 from the internet is in scope for this actor's first pass. If you do not already have an external inventory, How to Find Which of Your Admin Consoles Are Reachable From the Internet covers the method.
**Hunt backwards.** The advisory asks defenders to watch for unauthorised living-off-the-land tooling and unexpected Active Directory replication, high outbound or upload volumes from workstations, logons outside working hours, scanning-level traffic volumes, and unfamiliar IP addresses and ports in command lines, registry entries and firewallFirewallπSecurity system that monitors and controls network traffic based on predetermined rules. logs. Query DNS and proxy logs for the seized and C2 domains. The seizures mean those names no longer resolve to the operators, but a historical resolution is evidence of contact.
**Apply the advisory's mitigations in priority order.** Disable unused services and ports and minimise banner information. Sanitise web-application input to kill the XSS vector. Require MFA on webmail, VPN and every critical-system login. Audit and reduce administrative accounts. Review cloud tenants for connected applications with mail access. Replace end-of-life products. Each of these removes one stage of the pipeline described above.
Long-Term Outlook
This is the second time the US has disrupted Integrity Tech's operations, as US Attorney Troy Rivetti noted, after the Raptor Train takedown in September 2024. The Treasury sanctioned the company in January 2025, the UK followed in December 2025 and the EU in 2026. The company is still operating, and FishHub was active as recently as March 2026. Seizing seven domains interrupts a tool; it does not remove the contractor, the botnet, or the 1,300 scripts.
CISA's Acting Executive Assistant Director Chris Butera framed the intent plainly: Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology, with the aim of disrupting critical functions at a future time of their choosing. Read against the CVE list, that statement is the real warning. The access being pre-positioned was not bought with zero-days. It was bought with a 2015 FTP bug and a 2016 Struts bug on hosts nobody was tracking.
The procedural lesson is that the KEV catalogue is no longer only a feed of fresh zero-days. CISA will add a ten-year-old CVE with a three-day deadline the moment it has evidence of exploitation, and the burden shifts to defenders to prove no instance exists. Why 'We Patched That in 2015' Is Not an Answer to a KEV Deadline works through what that proof has to look like.
Sources
- CISA Known Exploited Vulnerabilities catalog JSON feed, version 2026.10.08: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- CISA, FBI, NSA and partners, joint Cybersecurity Advisory AA26-281A (8 October 2026): https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
- CISA news release on AA26-281A: https://www.cisa.gov/news-events/news/cisa-fbi-nsa-and-international-partners-warn-china-based-cybersecurity-company-enabling-threat
- US Department of Justice, "Justice Department and FBI Seize Vulnerability Scanning and Spear PhishingSpear Phishingπ‘οΈA targeted phishing attack directed at specific individuals or organizations, using personalized information to appear more legitimate and increase success rates. Tools Operated by China-Sponsored Hackers" (8 October 2026): https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated
- NVD records: https://nvd.nist.gov/vuln/detail/CVE-2015-3306, https://nvd.nist.gov/vuln/detail/CVE-2015-5477, https://nvd.nist.gov/vuln/detail/CVE-2016-3081, https://nvd.nist.gov/vuln/detail/CVE-2021-3199, https://nvd.nist.gov/vuln/detail/CVE-2023-22894
- The Hacker News, "Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies" (9 October 2026): https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html
- The Hacker News, "FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails" (8 October 2026): https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html
- BleepingComputer, "FBI disrupts Chinese hacking tools used to breach critical infrastructure" (8 October 2026): https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
- Help Net Security, "FBI disrupts Flax Typhoon hacking tools used in global cyberattacks" (9 October 2026): https://www.helpnetsecurity.com/2026/10/09/fbi-flax-typhoon-microscan-fishhub-domains/