Back to Articles
high

HIGH: Flax Typhoon Exploits Five Old Flaws as CISA Sets Weekend Deadline

CISA added five actively exploited flaws in ProFTPD, ONLYOFFICE, Strapi, Apache Struts and ISC BIND to its KEV catalog after a seven-nation advisory tied the attacks to Flax Typhoon and Beijing contractor Integrity Technology Group. Federal agencies must patch by October 11, 2026.

By Danny Mercer, CISSP — Lead Security Analyst • Oct 10, 2026
Is your business exposed? Our McKinney-based security team can assess your risk for free.
Share:

If you have been telling yourself that nobody bothers with decade-old bugs anymore, the U.S. government just published a rather pointed rebuttal. CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and the oldest of them was disclosed when the Apple Watch was still a novelty. The reason they landed in the catalog all at once is the part that should get your attention. Every one of them has been used by Flax Typhoon, the China-linked operation that a seven-nation joint advisory now ties directly to Integrity Technology Group, a Beijing contractor working on behalf of the Chinese government.

Federal civilian agencies have until October 11, 2026 to patch or pull the affected systems offline. That is a weekend deadline with roughly 72 hours of runway, which tells you how seriously CISA is taking this. For everyone outside the federal space, the deadline is not binding, but the threat absolutely is. Flax Typhoon does not care whether you are a cabinet agency or a regional credit union with a forgotten FTP box in the closet.

Five old bugs, one very patient adversary

The newly cataloged flaws read like a museum tour of internet history, and that is precisely the point. Attackers with state backing have scanners that never get bored, and they will happily try a 2015 exploit against your network because statistically somebody out there still has not patched it.

The headliner is CVE-2015-3306 in ProFTPD, which carries a perfect 10.0 CVSS score. The bug lives in the mod_copy module, which exposes the SITE CPFR and SITE CPTO commands to clients without requiring authentication. An unauthenticated attacker can use those commands to copy arbitrary files around the server, and the classic abuse is writing a PHP payload into a web root and then simply browsing to it. It was fixed in ProFTPD 1.3.5a back in 2015, which means anyone still exposed is running software that has been out of date for over ten years. Those systems exist. Shodan will cheerfully show you thousands of them.

Next up is CVE-2021-3199, a path traversal in ONLYOFFICE Document Server rated 9.8 on the CVSS scale. The flaw sits in how the server handles JWT tokens and file paths, and an attacker can smuggle directory traversal sequences through an image upload parameter to drop files wherever they like and work toward remote code execution. ONLYOFFICE fixed it in Document Server 5.6.3 and later. Plenty of organizations run ONLYOFFICE quietly behind Nextcloud or other collaboration stacks, so there is a real chance the people responsible for patching it do not even know it is there.

CVE-2016-3081 is an Apache Struts command injection with a CVSS score of 8.1 that hinges on configuration. When Dynamic Method Invocation is enabled, an attacker can pass a crafted method: prefix that gets evaluated as an OGNL expression, and that is game over for the application server. The fixes arrived in Struts 2.3.20.3, 2.3.24.3, and 2.3.28.1, and disabling Dynamic Method Invocation shuts the door even on unpatched builds. If the word Struts makes you flinch, that is a healthy reaction. This framework has been the root cause of more than one very public catastrophe.

The remaining two are less dramatic on paper but still earned their spots. CVE-2023-22894 in the Strapi headless CMS, rated 7.2, stores sensitive data such as password hashes and reset tokens in a way that lets someone with admin panel access pull them out through crafted query filters. Strapi fixed it in version 4.8.0 and later releases. CVE-2015-5477 in ISC BIND, rated 7.5, is a reachable assertion triggered by a malformed TKEY query, and a single packet can crash the named process. ISC patched it in BIND 9.9.7 P2 and 9.10.2 P3 back in July of that year. Knocking over DNS is not glamorous, but it makes a fine distraction while the real work happens elsewhere.

CISA also noted that three other flaws in the campaign were already in the catalog. Those are the Shellshock variant CVE-2014-6278, the Pulse Connect Secure file read CVE-2019-11510, and CVE-2021-22205, the GitLab ExifTool code execution bug. Taken together, the toolkit covers eight vulnerabilities used for initial access and data theft, and not one of them is newer than 2023.

Who is behind it and what they are doing

Flax Typhoon is not a new name. Microsoft started tracking the group years ago, and in 2024 the FBI took down a Mirai based botnet run by Integrity Technology Group that had swallowed more than 260,000 routers, cameras, and storage devices worldwide, roughly 126,000 of them in the United States. A database server tied to that operation held records for about 1.2 million compromised devices. Apparently the takedown was viewed in Beijing as a minor scheduling inconvenience.

The new joint advisory, signed by agencies from the United States, the United Kingdom, Australia, Canada, Japan, New Zealand, and Spain, describes a mature, industrialized operation. Alongside it, the FBI and the Justice Department seized seven domains used by the group and disrupted three of its tools. Microscan is a Python vulnerability scanner packed with more than 1,300 exploit and reconnaissance scripts targeting OpenSSL, Oracle WebLogic, Jenkins, Juniper ScreenOS, WordPress, and Apache Struts, glued together with familiar open source tools like masscan, Nmap, Fscan, and dirsearch. FishHub is a spear phishing platform used to deliver payloads and pull stolen files back to Integrity Tech servers. Sparrow is the command and control console for the group's Mirai derived IoT botnet.

The victim list explains why this rose to a multinational advisory. A power company in South Carolina was hit, as was a multinational NGO. Overseas, the operators reached into airports in Japan and Poland, natural gas and power operators in Taiwan, and more than twenty Taiwanese universities through FishHub alone. CISA's Chris Butera put it bluntly, warning that "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology systems" so they can cause disruption at a moment of their choosing.

The tradecraft is a blend of automation and old fashioned persistence. The advisory says the group pairs AI assisted scanning with large botnets and hands on keyboard exploitation. Once inside, operators have harvested credentials through cross site scripting, password sprayed Microsoft Exchange and Microsoft 365 accounts with a tool called EBurst, read mailboxes with a utility called office-cli, and installed SoftEther VPN to keep a quiet, encrypted tunnel back into the network. SoftEther is legitimate software, which is exactly why it is so attractive. It blends into the noise of a busy network unless someone is specifically looking for it.

The FBI's Brett Leatherman summed up the business model nicely when he said the PRC "relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity." In other words, this is outsourced espionage with a sales quota, and your unpatched server is inventory.

What to do this weekend

Start with an honest inventory, because you cannot patch what you do not know you own. Search your external attack surface for ProFTPD, ONLYOFFICE Document Server, Strapi, Apache Struts, and BIND, and do not stop at the obvious servers. These packages hide inside appliances, vendor supplied virtual machines, and that one Linux host a contractor set up in 2017 that everyone is afraid to reboot.

For ProFTPD, upgrade to a current release and, if you have no use for mod_copy, unload it entirely. Honestly, ask whether that FTP service needs to face the internet at all. For ONLYOFFICE, move to a current Document Server build, confirm JWT validation is enabled, and make sure the service is not directly reachable from the outside. Strapi users should be on 4.8.0 or later, and since the flaw exposes password hashes and reset tokens, rotate admin credentials after upgrading. Struts applications need either an upgraded framework or Dynamic Method Invocation explicitly turned off with struts.enable.DynamicMethodInvocation set to false, and frankly any Struts 2.3 application in 2026 deserves a conversation about retirement. BIND should be running a supported 9.18 or 9.20 branch, not a museum piece.

Then check the three older catalog entries as well. Pulse Connect Secure appliances that were vulnerable to CVE-2019-11510 leaked cleartext credentials, so if you ever ran a vulnerable build, assume those credentials were harvested and rotate them even if the box has since been patched or replaced.

Detection deserves equal attention, because patching does not evict anyone who is already inside. Hunt for SoftEther VPN binaries, services, or outbound connections on servers that have no business running a VPN client. Review Microsoft 365 and Exchange sign in logs for password spraying patterns, meaning many accounts failing from a small set of IP addresses, followed by a successful login. Watch your FTP logs for SITE CPFR and SITE CPTO commands, look for unexpected PHP or JSP files appearing in web roots, and alert on OGNL style strings or method: prefixes in web server request logs. Block the seized domains published in the advisory at DNS and the proxy, including outlook3650[.]com and linkedinns[.]net, which are named to look just familiar enough to pass a casual glance.

Finally, segment anything that touches operational technology. The victim list makes clear that Flax Typhoon is interested in power and gas infrastructure, and a flat network turns one stale web server into a path to the control room.

The MSP angle

This advisory is a gift for any MSP selling continuous external attack surface management and vulnerability scanning, because "a Chinese state contractor is exploiting ten year old bugs" is a far easier conversation with a client than abstract risk scores. Pair that with a Microsoft 365 identity hardening package and a managed threat hunt for persistence tools like SoftEther, and you have a concrete, timely offer that maps directly to what this adversary is doing right now.

References

Concerned about this threat?

Our security team can assess your exposure and recommend immediate actions.

Get a Free Assessment →