> Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
[DATE: 09/10/2026 12:21]
[LANGUAGE: EN]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.
The vulnerabilities in question are listed below -
CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow