The news here is not a fresh zero-day. It is the opposite. On October 8, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, and the newest of them is three years old. The oldest predates the catalog by a decade. Every one lives in software people run on their own servers: a DNS daemon, an FTP server, a web framework, a document server, and a headless content system. The same day, the FBI seized seven domains tied to a China-linked group that automates the hunt for exactly this kind of forgotten software. The story is about your own attic, not the newest appliance on the market.
If you operate self-hosted infrastructure, treat the list below as a hunt list, not a headline. The federal patch deadline is October 11, three days after listing, and the reason these bugs resurfaced tells you more than the bugs themselves.
What CISA flagged, and why it looks strange
CISA confirms every KEV entry is being exploited in the wild before it lists it, so all five carry evidence of real attacks, not theory. What stands out is their age. Four of the five were disclosed between 2015 and 2021, and CISA still attached a three-day remediation window, the kind of deadline you expect on a brand-new critical bug. An emergency clock on an eleven-year-old denial-of-service flaw is the tell: CISA is reacting to exploitation happening now, not to the original disclosure.
| Product | CVE | Disclosed | Flaw | What it gives an attacker |
|---|---|---|---|---|
| ISC BIND | CVE-2015-5477 | 2015 | DoS via TKEY query | Crashes the DNS server |
| ProFTPD | CVE-2015-3306 | 2015 | mod_copy file read/write | Arbitrary file access, often code execution |
| Apache Struts | CVE-2016-3081 | 2016 | Command injection | Remote code execution |
| ONLYOFFICE Docs | CVE-2021-3199 | 2021 | Path traversal on upload | Remote code execution |
| Strapi | CVE-2023-22894 | 2023 | Cleartext data exposure | Leaks user records, chainable to RCE |
The individual mechanics are modest by modern standards. CVE-2015-5477 crashes an ISC BIND nameserver with a malformed TKEY query, a pure denial of service. CVE-2015-3306 abuses ProFTPD's mod_copy module, where the unauthenticated SITE CPFR and SITE CPTO commands read and write arbitrary files. CVE-2016-3081 is command injection in Apache Struts, but only when Dynamic Method Invocation is switched on. CVE-2021-3199 is a path traversal in ONLYOFFICE Docs that reaches code execution through an image-upload parameter when JWT is in use. CVE-2023-22894 leaks user records from Strapi through a query filter, and CISA flags the affected builds as end-of-life, advising a move to a supported release. None of these is exotic. That is the point.
Why old and obscure stopped being safe
The same morning CISA updated the catalog, the FBI, CISA, and the National Security Agency published a joint advisory and the Department of Justice announced the seizure of seven domains. According to that reporting, the domains ran two tools, a Python scanner called MicroScan and a malware delivery system called FishHub, used by a China-linked group tracked as Flax Typhoon (also called Ethereal Panda and Red Juliett) to scan and breach critical infrastructure. US authorities allege the tooling and infrastructure came from a Beijing-based company, Integrity Technology Group. The agencies say MicroScan carries more than 1,300 penetration-testing scripts, including checks for flaws as old as the 2014 Shellshock bug.
That number is the real story. A human attacker rarely wakes up thinking about an FTP daemon from 2015. A scanner with 1,300 scripts does not think at all: it sweeps the entire internet and fires every check at every host it finds. Once a vulnerability is one line in that library, its age and its obscurity stop protecting you. "Nobody targets ProFTPD anymore" was never a control. It was a bet that no attacker would bother looking, and automated scanning at nation-state scale cancels that bet. We have watched the same dynamic in botnet takedowns, where seizing the infrastructure does not clean the hosts that were already found and compromised (as with the Sality takedown, and the NetNut proxy seizure). A domain seizure removes one operator's reach. It does not patch your server.
The services you forgot you run
Four of the five products are internet-facing server software that an operator stands up once and stops thinking about. A DNS server, an FTP service, a Struts application behind a web app, a document server bolted onto a collaboration tool. These are not the appliances a security team reviews each quarter. They are the long tail: the service a former admin installed for one project, the dependency three layers down in an app nobody owns anymore. The bug classes involved are the bread and butter of mass exploitation, not edge cases. In our own 90-day triage ledger, command injection and remote code execution, along with path traversal and arbitrary file access, rank among the most common flaw types we log. These are the categories scanners are built to find.
So the first move is not patching. It is inventory. You cannot patch BIND on a host you forgot answers DNS, and you cannot retire an end-of-life Strapi build you did not know was still serving. Map what is actually listening on your internet-facing hosts, then match it against the five products below. The exposure that bites you is the service you would not have named if asked. The same reasoning applies to every unmaintained self-hosted app, which is why self-hosted web stacks and legacy network gear keep returning to the KEV catalog.
How to tell if a scanner already found you
Patching closes the hole. It does not tell you whether the three-day window, or the years before this listing, already cost you something. Each of these flaws leaves a different trace, and a denial-of-service bug like the BIND issue is the easy one to miss: the only signal is the service restarting, so alert on named dying and respawning, not on patch state alone. For the others, the observables are in the logs the affected product already writes.
ISC BIND named exits then restarts; assertion failures around TKEY handling ProFTPD SITE CPFR / SITE CPTO commands in the transfer and system logs Apache Struts a method: prefix on a request to an .action endpoint in access logs ONLYOFFICE a /.. sequence inside an image-upload request path Strapi unexpected query-filter parameters probing admin user fields
None of this requires a product you do not already run. A service that watches your own server logs and maps the hits to attacker behavior, which is what a managed detection service does, turns these lines into an alert instead of a line nobody reads. The point is that the detection lives in logs you already generate, whether or not anyone is reading them today.
Inventory the services you forgot, then patch by October 11
The concrete work is short. First, enumerate what your internet-facing hosts are actually running and find any instance of BIND, ProFTPD, Apache Struts, ONLYOFFICE Docs, or Strapi. Second, patch or upgrade each to a current, supported release, retiring the end-of-life Strapi builds CISA called out rather than trying to fix them in place. Third, for anything you cannot patch by the October 11 deadline, pull it off the public internet or put it behind authentication while you catch up. The broader takeaway outlasts these five CVEs: when a state-linked group industrializes scanning, every unmaintained service you expose is a target on a schedule, and the age of its last vulnerability is no comfort at all.