
Photo credits
CISA Adds Five Software Flaws to Known Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency has listed five critical flaws that attackers are actively using against networks.
11 Oct 2026
#CISA #ProFTPD #ONLYOFFICE Docs #Strapi #Apache Struts #ISC BIND
The U.S. Cybersecurity and Infrastructure Security Agency added five vulnerabilities to its Known Exploited Vulnerabilities catalog on October 11, 2026. This list tracks security holes that hackers are currently exploiting in the wild. Federal agencies must fix these issues by the due date to stay protected.
The new entries include flaws in ProFTPD and ONLYOFFICE Docs software. One issue in ProFTPD allows attackers to read or change files without permission, rated at a CVSS score of 10.0. Another flaw in ONLYOFFICE Docs lets attackers run code remotely through image uploads with a score of 9.8.
Strapi, Apache Struts, and ISC BIND are also part of the update. The Strapi vulnerability exposes user details stored without encryption and carries a score of 7.2. A problem in Apache Struts allows remote code execution if certain settings are enabled with a score of 8.1. ISC BIND has a weakness that could stop services from working properly rated at 7.5.
These five flaws link to cyber operations by actors tied to Integrity Technology Group. This is a China-based cybersecurity company according to U.S. authorities. The activity involved exploiting eight vulnerabilities to steal information from targeted networks.

Photo credits
U.S. officials seized tools called Microscan and FishHub in response to these operations. Microscan scans networks to find weak systems for attack. FishHub uses fake emails to deliver malware and steal files or credentials.
The attackers used scanning tools and password spraying against Microsoft Exchange servers. They also relied on VPN software to keep access open inside the networks. Scripts helped them extract emails and other sensitive data during the campaign.
A joint advisory issued by seven countries highlights this shared risk. The group includes Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States. This coordinated action aims to disrupt infrastructure used for cyber operations linked to China.
Binding Operational Directive 22-01 requires federal agencies to address these flaws quickly. Agencies must fix the identified vulnerabilities by October 11, 2026. Experts also recommend private organizations review the catalog and patch their own systems.