US Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after identifying active exploitation linked to the threat actor known as Flax Typhoon. According to CISA, the vulnerabilities affect a range of widely used enterprise technologies, including ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND. The agency said the additions follow observed activity in which the vulnerabilities were used to gain initial access to targeted environments. As part of its Binding Operational Directive process, CISA has instructed U.S. federal civilian agencies to remediate the affected systems or discontinue their use by October 11, 2026. The latest KEV updates highlight the continued importance of timely patch management as organizations face increasingly sophisticated intrusion campaigns targeting known software weaknesses.
The advisory coincides with a joint cybersecurity warning issued by authorities from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States regarding cyber activity attributed to a China linked cybersecurity company identified as Integrity Technology Group. According to the advisory, operations associated with Flax Typhoon have targeted eight publicly known vulnerabilities to establish initial access into organizational networks and obtain sensitive information. The campaign reportedly combines vulnerability scanning, cross site scripting techniques, and password spraying against Microsoft Exchange environments before establishing persistence through virtual private network software. The advisory also states that scripts were used to collect email data and user credentials from compromised systems. Of the eight vulnerabilities referenced in the warning, five have now been newly added to the KEV Catalog, while three others, including Shellshock, an Ivanti Pulse Connect Secure vulnerability, and a GitLab remote code execution flaw, had already been included in previous years because of earlier exploitation activity.
CISA noted that the newly added vulnerabilities cover multiple categories of security weaknesses, including improper access control, path traversal, command injection, denial of service, and cleartext storage of sensitive information. These flaws affect products that continue to be deployed across enterprise and government environments, making them attractive targets for threat actors seeking initial network access. According to the joint advisory, the reported activity demonstrates how publicly disclosed vulnerabilities can remain valuable to attackers when systems are not updated promptly. Acting Executive Assistant Director for Cybersecurity Chris Butera stated that government affiliated cyber actors continue attempting to position themselves within critical infrastructure environments, including operational technology systems, with the objective of maintaining access that could potentially be used to disrupt essential services in the future. The statement reinforces ongoing concerns surrounding the protection of critical infrastructure from persistent cyber campaigns.
The latest KEV additions serve as another reminder for public and private sector organizations to regularly review vulnerability management programs, monitor vendor security updates, and prioritize remediation of flaws that are known to be actively exploited. While the October 11 deadline specifically applies to U.S. federal civilian agencies under CISA requirements, the vulnerabilities affect software products used globally, making the advisory relevant for enterprises beyond the federal sector. Security teams are encouraged to assess whether affected technologies are present within their environments, verify that the latest available patches have been applied, and review systems for any indicators of unauthorized activity. Maintaining an accurate inventory of internet facing assets and implementing timely updates remain key measures for reducing exposure to known exploitation techniques documented by government cybersecurity agencies.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.