Flax Typhoon exploits decade-old CVEs: patch your old servers
A 7-nation advisory says Flax Typhoon hits ProFTPD, Strapi, ONLYOFFICE and Struts bugs up to 11 years old. CISA's KEV deadline is today. Find your forgotten boxes.
Flax Typhoon is exploiting decade-old CVEs, not zero-days. On October 8, the FBI, CISA, NSA and agencies from six other countries published a joint advisory on Integrity Technology Group, a China-based security company tied to the Flax Typhoon hacking activity. The list of bugs it used reads like a museum: a 2015 ProFTPD flaw, a 2016 Apache Struts flaw, Shellshock from 2014. CISA added five of them to its Known Exploited Vulnerabilities catalog the same day, and the federal deadline to patch is today, October 11. If you run a self-hosted FTP server, CMS or document editor that nobody has touched in years, this one is about you.
What actually happened
The advisory, AA26-281A, names eight CVEs that the group exploited successfully. Five were new to the KEV catalog:
- CVE-2015-3306, ProFTPD. Unauthenticated file read and write through the
site cpfr/site cptocommands. CVSS 10.0. - CVE-2021-3199, ONLYOFFICE Docs. Path traversal in image upload when JWT is on, which can lead to code execution. CVSS 9.8.
- CVE-2016-3081, Apache Struts. Command injection when Dynamic Method Invocation is enabled.
- CVE-2023-22894, Strapi. An attacker with admin panel access can pull sensitive user data through query filters.
- CVE-2015-5477, ISC BIND. A crafted TKEY query crashes the DNS server.
The other three were already on the list: Shellshock (CVE-2014-6278), Pulse Connect Secure (CVE-2019-11510) and GitLab (CVE-2021-22205). The Hacker News reports the October 11 KEV due date. The advisory also describes password spraying against Microsoft Exchange, and SoftEther VPN clients installed under fake Windows process names like conhost.exe to keep access.
The same day, the DOJ and FBI seized seven domains tied to two of the company's tools: MicroScan, a Python scanner with more than 1,300 attack scripts that ran alongside a Mirai-infected botnet, and FishHub, a spear-phishing and malware-delivery platform, per BleepingComputer. Seizing a domain stops new scans. It does not clean a server that is already compromised.
Why old CVEs matter for your business
Nation-state crews use old bugs because old bugs still work. The box that gets you is not the app your team ships every week. It is the FTP server a former contractor set up in 2017, the Strapi admin that still has the default user, the GitLab instance nobody upgraded after the migration.
What we would do this week:
- Inventory what faces the internet. Run an external scan of your own IP ranges and domains. The advisory asks for the same thing: attack surface management.
- Kill what you do not need. FTP in 2026 is almost always replaceable with SFTP or object storage.
- Patch or retire anything on the eight-CVE list. An end-of-life product does not get a patch. It gets replaced.
- Put MFA on webmail and VPN. Password spraying only works without it.
- Look for VPN software you did not install. SoftEther on a server is a red flag.
Key takeaways
- A seven-nation advisory (AA26-281A) lists eight CVEs that Flax Typhoon-linked operators exploited, some from 2014 and 2015
- Five, including ProFTPD, Strapi and ONLYOFFICE, joined CISA's KEV catalog on October 8 with an October 11 deadline
- The DOJ and FBI seized domains for the MicroScan scanner and FishHub phishing tool, but seizures do not clean infected machines
- Your risk is the forgotten self-hosted box, not the app you deploy every week
- Scan your external footprint, retire end-of-life software, and require MFA on email and VPN
Not sure what your business still has open to the internet? We find the old FTP servers, stale CMS admins and orphaned GitLab boxes, then patch, migrate or shut them down. Book an exposure review, or see how we maintain what we build.
Sources: CISA advisory AA26-281A, CISA news release, The Hacker News, BleepingComputer.
- #cybersecurity
- #flax-typhoon
- #cisa-kev
- #patch-management
- #self-hosted
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
NetScaler CVE-2026-107406: last week's SAML patch isn't enough
Citrix NetScaler CVE-2026-107406 (CVSS 9.5) hits SAML IdP builds up to 14.1-73.41, the fix for last week's KEV bug. Patch to 14.1-73.46 or 13.1-64.29.
Read itHarness buys Augment Code assets: coding agents consolidate
Harness bought Augment Code's Cosmos, Auggie CLI and Context Engine. Coding agent vendors are consolidating. Keep your context and workflow portable.
Read it