Home/ Blog/ Security news/ Article
Blog · Security news

Flax Typhoon Scanners Mass-Exploit Five Legacy Server Bugs in CISA KEV

CISA added five legacy self-hosted server flaws (BIND, ProFTPD, Struts, ONLYOFFICE, Strapi) to its KEV catalog as China-linked scanners exploit them.

Half-buried dormant machine modules on open ground, a thin beam sweeping above them

The news here is not a fresh zero-day. It is the opposite. On October 8, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, and the newest of them is three years old. The oldest predates the catalog by a decade. Every one lives in software people run on their own servers: a DNS daemon, an FTP server, a web framework, a document server, and a headless content system. The same day, the FBI seized seven domains tied to a China-linked group that automates the hunt for exactly this kind of forgotten software. The story is about your own attic, not the newest appliance on the market.

If you operate self-hosted infrastructure, treat the list below as a hunt list, not a headline. The federal patch deadline is October 11, three days after listing, and the reason these bugs resurfaced tells you more than the bugs themselves.

What CISA flagged, and why it looks strange

CISA confirms every KEV entry is being exploited in the wild before it lists it, so all five carry evidence of real attacks, not theory. What stands out is their age. Four of the five were disclosed between 2015 and 2021, and CISA still attached a three-day remediation window, the kind of deadline you expect on a brand-new critical bug. An emergency clock on an eleven-year-old denial-of-service flaw is the tell: CISA is reacting to exploitation happening now, not to the original disclosure.

ProductCVEDisclosedFlawWhat it gives an attacker
ISC BINDCVE-2015-54772015DoS via TKEY queryCrashes the DNS server
ProFTPDCVE-2015-33062015mod_copy file read/writeArbitrary file access, often code execution
Apache StrutsCVE-2016-30812016Command injectionRemote code execution
ONLYOFFICE DocsCVE-2021-31992021Path traversal on uploadRemote code execution
StrapiCVE-2023-228942023Cleartext data exposureLeaks user records, chainable to RCE
The five flaws CISA added to its Known Exploited Vulnerabilities catalog on October 8, 2026. Source: CISA KEV catalog.

The individual mechanics are modest by modern standards. CVE-2015-5477 crashes an ISC BIND nameserver with a malformed TKEY query, a pure denial of service. CVE-2015-3306 abuses ProFTPD's mod_copy module, where the unauthenticated SITE CPFR and SITE CPTO commands read and write arbitrary files. CVE-2016-3081 is command injection in Apache Struts, but only when Dynamic Method Invocation is switched on. CVE-2021-3199 is a path traversal in ONLYOFFICE Docs that reaches code execution through an image-upload parameter when JWT is in use. CVE-2023-22894 leaks user records from Strapi through a query filter, and CISA flags the affected builds as end-of-life, advising a move to a supported release. None of these is exotic. That is the point.

Why old and obscure stopped being safe

The same morning CISA updated the catalog, the FBI, CISA, and the National Security Agency published a joint advisory and the Department of Justice announced the seizure of seven domains. According to that reporting, the domains ran two tools, a Python scanner called MicroScan and a malware delivery system called FishHub, used by a China-linked group tracked as Flax Typhoon (also called Ethereal Panda and Red Juliett) to scan and breach critical infrastructure. US authorities allege the tooling and infrastructure came from a Beijing-based company, Integrity Technology Group. The agencies say MicroScan carries more than 1,300 penetration-testing scripts, including checks for flaws as old as the 2014 Shellshock bug.

That number is the real story. A human attacker rarely wakes up thinking about an FTP daemon from 2015. A scanner with 1,300 scripts does not think at all: it sweeps the entire internet and fires every check at every host it finds. Once a vulnerability is one line in that library, its age and its obscurity stop protecting you. "Nobody targets ProFTPD anymore" was never a control. It was a bet that no attacker would bother looking, and automated scanning at nation-state scale cancels that bet. We have watched the same dynamic in botnet takedowns, where seizing the infrastructure does not clean the hosts that were already found and compromised (as with the Sality takedown, and the NetNut proxy seizure). A domain seizure removes one operator's reach. It does not patch your server.

The services you forgot you run

Four of the five products are internet-facing server software that an operator stands up once and stops thinking about. A DNS server, an FTP service, a Struts application behind a web app, a document server bolted onto a collaboration tool. These are not the appliances a security team reviews each quarter. They are the long tail: the service a former admin installed for one project, the dependency three layers down in an app nobody owns anymore. The bug classes involved are the bread and butter of mass exploitation, not edge cases. In our own 90-day triage ledger, command injection and remote code execution, along with path traversal and arbitrary file access, rank among the most common flaw types we log. These are the categories scanners are built to find.

So the first move is not patching. It is inventory. You cannot patch BIND on a host you forgot answers DNS, and you cannot retire an end-of-life Strapi build you did not know was still serving. Map what is actually listening on your internet-facing hosts, then match it against the five products below. The exposure that bites you is the service you would not have named if asked. The same reasoning applies to every unmaintained self-hosted app, which is why self-hosted web stacks and legacy network gear keep returning to the KEV catalog.

How to tell if a scanner already found you

Patching closes the hole. It does not tell you whether the three-day window, or the years before this listing, already cost you something. Each of these flaws leaves a different trace, and a denial-of-service bug like the BIND issue is the easy one to miss: the only signal is the service restarting, so alert on named dying and respawning, not on patch state alone. For the others, the observables are in the logs the affected product already writes.

What to grep on the affected hosts
ISC BIND      named exits then restarts; assertion failures around TKEY handling
ProFTPD       SITE CPFR / SITE CPTO commands in the transfer and system logs
Apache Struts a method: prefix on a request to an .action endpoint in access logs
ONLYOFFICE    a /.. sequence inside an image-upload request path
Strapi        unexpected query-filter parameters probing admin user fields

None of this requires a product you do not already run. A service that watches your own server logs and maps the hits to attacker behavior, which is what a managed detection service does, turns these lines into an alert instead of a line nobody reads. The point is that the detection lives in logs you already generate, whether or not anyone is reading them today.

Inventory the services you forgot, then patch by October 11

The concrete work is short. First, enumerate what your internet-facing hosts are actually running and find any instance of BIND, ProFTPD, Apache Struts, ONLYOFFICE Docs, or Strapi. Second, patch or upgrade each to a current, supported release, retiring the end-of-life Strapi builds CISA called out rather than trying to fix them in place. Third, for anything you cannot patch by the October 11 deadline, pull it off the public internet or put it behind authentication while you catch up. The broader takeaway outlasts these five CVEs: when a state-linked group industrializes scanning, every unmaintained service you expose is a target on a schedule, and the age of its last vulnerability is no comfort at all.

Topics

Frequently asked questions

What did CISA add to its KEV catalog on October 8, 2026?

CISA added five actively exploited flaws: CVE-2015-5477 in ISC BIND, CVE-2015-3306 in ProFTPD, CVE-2016-3081 in Apache Struts, CVE-2021-3199 in ONLYOFFICE Docs, and CVE-2023-22894 in Strapi. All five affect self-hosted server software, with a federal patch deadline of October 11.

Why would decade-old CVEs get an emergency patch deadline?

CISA lists a vulnerability only after confirming active exploitation in the wild, so the fresh event is current attacks, not the original disclosure. A China-linked group is scanning the internet at scale for these flaws, which is why bugs from 2015 and 2016 now carry a three-day window.

Who is Flax Typhoon and what is MicroScan?

Flax Typhoon is a China-linked threat group, also tracked as Ethereal Panda and Red Juliett. According to a joint FBI, CISA, and NSA advisory, it used a Python scanner called MicroScan and a delivery tool called FishHub, allegedly supplied by Beijing-based Integrity Technology Group, to scan and breach critical infrastructure.

Do these flaws affect me if I run self-hosted services?

If any internet-facing host runs BIND, ProFTPD, Apache Struts with Dynamic Method Invocation enabled, ONLYOFFICE Docs with JWT, or an end-of-life Strapi build, yes. The risk is highest for forgotten or unmaintained services, which automated scanners find regardless of how obscure you assume they are.

How do I detect exploitation of these vulnerabilities?

Each flaw leaves a trace in the affected product's own logs: SITE CPFR or SITE CPTO commands for ProFTPD, a method prefix on an .action request for Struts, a traversal sequence in ONLYOFFICE image uploads, and odd query filters for Strapi. For the BIND denial of service, watch for the named process dying and restarting.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.