Skip to content
Quantum Secure Labs
Cybersecurity News

Flax Typhoon exploits eight flaws in common software, and Spain signs the joint advisory

Flax Typhoon, a China-linked group, is exploiting eight flaws in widely used software, and CISA added five to its KEV catalog on 8 October. Spain co-signs the joint advisory. It affects companies running their own…

By Quantum Secure Labs4 min read
Armario de servidores en una sala técnica con cables de red conectados
In this article

Flax Typhoon, a China-linked group, is exploiting eight flaws in widely used software, and CISA added five to its KEV catalog on 8 October. Spain co-signs the joint advisory. It affects companies running their own internet-facing servers: FTP, online office suites, CMS, on-premises Exchange, GitLab or VPN. Check what you expose and patch this week.

Key facts

  • CISA added five flaws to its Known Exploited Vulnerabilities (KEV) catalog on 8 October 2026. US federal agencies must patch them or stop using the software before 11 October.
  • The five new entries: CVE-2015-3306 in ProFTPD (CVSS 10.0), CVE-2021-3199 in ONLYOFFICE Docs (9.8), CVE-2016-3081 in Apache Struts (8.1), CVE-2015-5477 in ISC BIND (7.5) and CVE-2023-22894 in Strapi (7.2).
  • The other three were already in KEV: Shellshock (CVE-2014-6278), Ivanti Pulse Connect Secure (CVE-2019-11510) and GitLab (CVE-2021-22205).
  • The joint advisory is signed by Australia, Canada, Japan, New Zealand, Spain, the UK and the US, and names Chinese company Integrity Technology Group as an enabler of the attacks.
  • Observed techniques: scanning, cross-site scripting, password spraying against Exchange, persistence via VPN software, and theft of emails and credentials using scripts.

Does this affect a small company?

Yes, if you run your own servers reachable from the internet. You don't need to be critical infrastructure. The flaws sit in software many SMEs installed years ago and never touched again.

According to The Hacker News, the ProFTPD flaw lets attackers read and write arbitrary files using the site cpfr and site cpto commands. The ONLYOFFICE Docs flaw is a JWT-related path traversal that can lead to remote code execution. The Struts flaw allows command injection when Dynamic Method Invocation is enabled. Strapi stores sensitive information in cleartext. BIND can be knocked over with crafted TKEY queries.

If you have an old FTP server, a self-hosted online document server, a Strapi CMS, a Java app built on Struts, a BIND DNS server, self-hosted GitLab, an Ivanti Pulse Secure VPN or on-premises Exchange, you're on the list.

What if I use Microsoft 365 or cloud services?

Your direct risk is lower. The Exchange attacks described target servers, using password spraying (trying common passwords across many accounts) and cross-site scripting. If your email runs on Microsoft 365 or your tools are managed services, patching is the provider's job. Still, get written confirmation: many companies think they're fully in the cloud and still have a hybrid Exchange or a forgotten server.

Why do flaws from 2015 or 2016 matter?

Because they still work. Three of the five new entries carry 2015 or 2016 identifiers, and the most severe, in ProFTPD, scores CVSS 10.0. A state-backed group using them now means it keeps finding unpatched servers. An old flaw is not a fixed flaw.

What to do today

  1. Ask your IT team or provider for an inventory of everything published to the internet.
  2. Check for ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, ISC BIND, GitLab, Ivanti Pulse Secure or on-premises Exchange.
  3. Patch whatever has an update. Remove or isolate anything out of support.
  4. On Exchange, review logs for mass failed sign-ins and enforce MFA on every account.
  5. Review VPN and admin accounts: look for logins or new accounts nobody recognises.
  6. If everything is in the cloud, ask your provider to confirm no on-premises component remains exposed.

What it means for an SME

This is a hygiene alert, not an emergency. But two details are worth your attention.

First: Spain signs the advisory. This isn't a US agency problem arriving by accident; Spanish authorities consider this campaign relevant here.

Second: none of these flaws is new. The attacker doesn't need an unknown vulnerability. A server nobody remembers setting up is enough. That's why the most valuable step isn't buying a tool, it's knowing what you expose. If you can't answer that in an afternoon, that's your real risk.

Persistence through VPN software also deserves attention: an attacker who gets in and installs their own access can stay inside after you patch. Patching without reviewing accounts and access leaves the job half done.

If you need help building that inventory or reviewing access, our cybersecurity team works on exactly this.

Frequently asked questions

Do I have to patch before 11 October?

That deadline only binds US federal agencies. For you it's a signal of urgency: if you expose any of this software, act this week.

What is the KEV catalog?

It's CISA's list of vulnerabilities with confirmed exploitation. A flaw on it is being used in real attacks, not just in theory.

Is enabling MFA enough?

It helps a lot against password spraying on Exchange, but it doesn't fix flaws like the ones in ProFTPD or Struts. You still need to patch or remove the software.

Sources

Worried about a threat like this one?

We review your exposure and show you how to protect yourself.

See our cybersecurity service

Cybersecurity News

Attackers exploit two unpatched AhsayCBS flaws, and the latest version, 10.3.4, is still vulnerable

Attackers are exploiting two unpatched flaws in AhsayCBS, a backup management console popular with IT providers, to run code remotely. Even the latest version, 10.3.4, is affected. If an MSP or integrator handles your…

Cybersecurity News

FortiBleed is still active: FBI warns of attacks on FortiGate firewalls using stolen credentials

The FBI and the US Secret Service warn that FortiBleed is still active: attackers are getting into Fortinet FortiGate firewalls and SSL VPNs with stolen or reused credentials, sometimes locking administrators out. If…

Cybersecurity News

Attackers are exploiting critical CVE-2026-21589 in Jira and Confluence Data Center

Since 7 October, attackers have been trying to exploit CVE-2026-21589, a critical flaw that lets anyone read files without authentication in eight self-hosted Atlassian Data Center products, including Jira, Confluence…

Want to apply these ideas to your business?

Tell us about your case and we'll show you how to apply these strategies to your project.