HomeSecurityFlax Typhoon exploits five vulnerabilities

Flax Typhoon exploits five vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of five new security vulnerabilities to its list of Known Exploitable Vulnerabilities (KEV). The move comes after a China-linked threat actor known as Flax Typhoon. The move underscores the growing concern about cybersecurity and the need for increased vigilance by organizations and governments worldwide.

See also: Salt Typhoon: Exploits vulnerabilities in routers

Article Image: Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
Flax Typhoon exploits five vulnerabilities

The vulnerabilities mentioned are the following:

  • CVE-2015-3306 (CVSS score: 10.0): This vulnerability concerns improper access control in ProFTPD, allowing remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. ProFTPD is a widely used FTP server, and exploitation of this vulnerability could lead to serious data breaches.
  • CVE-2021-3199 (CVSS score: 9.8): This path vulnerability in ONLYOFFICE Docs can occur when JSON Web Token (JWT) is used. Through a “/..” sequence in an image upload parameter, attackers can achieve remote code execution. ONLYOFFICE Docs is a popular collaboration platform, and exploiting this vulnerability could allow access to sensitive documents.
  • CVE-2023-22894 (CVSS score: 7.2): This vulnerability concerns the storage of sensitive information in plain text in Strapi. An attacker with access to the admin panel can discover sensitive user details through the query filter. Strapi is a popular tool for API development, and exploiting this vulnerability could lead to the leakage of personal data.
  • CVE-2016-3081 (CVSS score: 8.1): This command injection vulnerability in Apache Struts could allow a remote attacker to execute arbitrary code via the method:prefix when Dynamic Method Invocation is enabled. Apache Struts is a web application development framework, and exploitation of this vulnerability could lead to a complete compromise of the application.
  • CVE-2015-5477 (CVSS score: 7.5): This assertion vulnerability in ISC BIND could allow a remote attacker to cause a denial of service via TKEY queries. ISC BIND is one of the most widely used DNS servers, and exploiting this vulnerability could disrupt access to critical network services.

The addition of the five vulnerabilities coincides with a joint warning issued by Australia, Canada, Japan, New Zealand, Spain, the United Kingdom and the United States. This warning refers to attacks facilitated by a Chinese cybersecurity firm known as Integrity Technology Group. These firms have been found to target eight security vulnerabilities, including the five listed above, to gain initial access to organizations and extract sensitive data.

See also: CISA: Guide to protecting networks from Chinese hackers Salt Typhoon

CVE-2026-51990 critical vulnerability Sogou Input Method Tencent hackers

The activity includes exploiting vulnerabilities using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers. The attackers establish a persistent presence via VPN software and extract emails and credentials using scripts. These techniques indicate a coordinated effort to gain long-term access to critical infrastructure.

It is worth noting that the remaining three vulnerabilities already have a place on the KEV list:

  • CVE-2014-6278: Command injection vulnerability in the GNU Bash operating system (also known as Shellshock), added in October 2025.
  • CVE-2019-11510: Arbitrary file read vulnerability in Ivanti Pulse Connect Secure, added in November 2021.
  • CVE-2021-22205: Remote code execution vulnerability in GitLab Community and Enterprise Edition, added in November 2021.

Deputy Executive Director for Cybersecurity, Chris Butera, stated that “hackers affiliated with the Chinese government continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the goal of disrupting critical operations at a future time of their choosing.” This statement underscores the need for increased vigilance and immediate action by organizations to protect their infrastructure.

See also: US: Warns about Chinese hackers “Typhoon”

Flax Typhoon exploits five vulnerabilities

Due to active exploitation, federal agencies are required to implement the necessary fixes or discontinue use by October 11, 2026. This deadline underscores the severity of the threat and the need for immediate action to protect critical systems from potential attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS