CISA KEV Alert: Five Legacy Flaws Exploited by China-Linked Actors
CISA put six exploited vulnerabilities on its Known Exploited Vulnerabilities list this week. One is a fresh NetScaler SAML zero-day. The other five are bugs from 2015 to 2023 that a China-linked contractor has been using, and federal agencies have until Sunday to deal with them.
What: Six CVEs added to CISA KEV from Saturday, October 3 to Friday, October 9, 2026: Citrix NetScaler CVE-2026-88779, plus ISC BIND CVE-2015-5477, Apache Struts CVE-2016-3081, Strapi CVE-2023-22894, ONLYOFFICE Docs CVE-2021-3199 and ProFTPD CVE-2015-3306.
Status: All six are confirmed exploited per CISA. The five October 8 additions appear in an FBI-led joint advisory on Integrity Technology Group, the company tied to Flax Typhoon activity.
Deadline: NetScaler: October 7 (passed). The other five: Sunday, October 11, 2026.
Fix: Upgrade each product to the fixed release listed below, or take it offline. Four of the six carry CISA’s forensic-triage flag, so check for compromise as well.
Key takeaways
- CISA added six exploited CVEs to KEV this week: one on October 4 (Citrix NetScaler CVE-2026-88779) and five on October 8 (BIND, Struts, Strapi, ONLYOFFICE and ProFTPD).
- Five deadlines land on Sunday, October 11. CISA gave federal agencies three days, which means weekend work for anyone tracking KEV dates.
- The October 8 batch is old software, not new zero-days. The CVE IDs date from 2015 to 2023, and every one already has a published fix. They are on the list because the FBI and partners say a China-linked company exploited them.
- Four of the six are flagged for forensic triage. CISA’s KEV data marks Struts, Strapi, ONLYOFFICE and ProFTPD with “forensicTriage: Yes,” so patching alone is not the whole job.
- The NetScaler deadline has already passed. If any SAML-enabled NetScaler is still below 14.1-73.41 or 13.1-64.28, it is overdue.
Executive Summary
This week’s KEV list is short, but it asks two different things of you.
The first item is familiar. On Sunday, October 4, CISA added CVE-2026-88779, a memory overflow in Citrix NetScaler ADC and Gateway appliances configured for SAML, with a three-day deadline. DataWater covered it in detail in our NetScaler SAML zero-day briefing. The deadline was Wednesday, October 7.
The second item is unusual. On Thursday, October 8, the FBI, CISA, NSA and international partners published joint advisory AA26-281A on Integrity Technology Group, a China-based company with links to the Chinese government. The agencies say Integrity Tech enables actors whose methods are consistent with activity publicly tracked as Flax Typhoon, Ethereal Panda and RedJuliett, while cautioning that those industry labels are not necessarily a one-to-one match. The advisory lists eight exploited vulnerabilities. That evening, CISA’s catalog (version 2026.10.08) added five of them, all with an October 11 due date. The other three—Bash, Pulse Connect Secure and GitLab—were already in the catalog, so this briefing does not count them as new.
The bottom line: confirm NetScaler is done, then search your environment for five pieces of old software you may have forgotten you run. If you find one exposed to the internet, assume it was scanned and check it for compromise.
Why This Matters to CISOs and Security Leaders
Old bugs are a bigger risk than they look. A 2015 ProFTPD or 2016 Struts flaw tends to live on systems nobody owns: a forgotten FTP host, a legacy Java app, an appliance that bundles an old library. CISA’s notes on four of the five October 8 entries say the flaw may sit in an open-source component used by other products. That means your scanner may not find it under the name you expect.
A state-linked actor is scanning at scale. According to BleepingComputer, MicroScan carries more than 1,300 attack scripts and was paired with a Mirai botnet. Targets included a South Carolina power company, airports in Japan and Poland, and Taiwanese energy firms. The FBI has not said whether those named targets were breached. Your internet-facing estate is exactly what this kind of tool looks for.
The edge-device run continues. NetScaler CVE-2026-88779 follows the PitScaler zero-days by about a week, and last week’s KEV list also included FortiMail and Cisco SD-WAN, recapped in our week-ending October 3 briefing.
Ask your vulnerability team one question today: “Can you prove we don’t run ProFTPD 1.3.5, Struts 2.3, Strapi before 4.8.0, ONLYOFFICE Document Server before 5.6.3 or an old BIND anywhere, including inside vendor appliances?” If the answer is “probably not,” that is your weekend priority.
The Timeline
| Date (2026) | What happened |
|---|---|
| Saturday, Oct 3 | Citrix publishes bulletin CTX697174 for CVE-2026-88779 with fixed builds (Pacific time) |
| Sunday, Oct 4 | CISA adds CVE-2026-88779 to KEV; due October 7 |
| Wednesday, Oct 7 | NetScaler CVE-2026-88779 federal deadline |
| Thursday, Oct 8 | FBI and partners publish a joint advisory on Integrity Technology Group; BleepingComputer reports seven domains seized |
| Thursday, Oct 8 (evening UTC) | CISA KEV catalog version 2026.10.08 adds CVE-2015-5477, CVE-2016-3081, CVE-2023-22894, CVE-2021-3199 and CVE-2015-3306 |
| Sunday, Oct 11 | Federal deadline for all five October 8 additions |
None of this week’s five new KEV entries needed a new patch. They needed someone to remember the server was there.
Vulnerability & Exploit Analysis
One section per CVE, in the order CISA added them. Due dates are CISA’s federal deadlines.
1. Citrix NetScaler ADC and Gateway: CVE-2026-88779
Product: NetScaler ADC and NetScaler Gateway, only when configured as a SAML Service Provider or SAML Identity Provider. Citrix says Secure Private Access hybrid deployments that use NetScaler are also affected. Flaw: a memory overflow (CWE-119) that Citrix says lets an unauthenticated remote attacker cause denial of service. Citrix scores it CVSS v4.0 8.7. Added: October 4. Due: October 7. First action: search configs for add authentication samlAction or add authentication samlIdPProfile and upgrade those appliances to 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS; FIPS/NDcPP: 13.1-37.282) or later. Field reports of payload attempts are covered in our full CVE-2026-88779 briefing.
2. ISC BIND: CVE-2015-5477
Product: ISC BIND named. Flaw: a crafted TKEY query triggers an assertion failure that makes the DNS server exit, causing a remote denial of service. NVD scores it CVSS v2 7.8. Added: October 8. Due: October 11. First action: find any BIND older than 9.9.7-P2 (9.9 branch) or 9.10.2-P3 (9.10 branch), including inside appliances, and upgrade to a supported release.
3. Apache Struts: CVE-2016-3081 (S2-032)
Product: Apache Struts 2.3.20 through 2.3.28, except 2.3.20.3 and 2.3.24.3. Flaw: remote code execution through the method: prefix when Dynamic Method Invocation is turned on. Added: October 8. Due: October 11. CISA flags it for forensic triage. First action: inventory Java applications for Struts 2.3 libraries, upgrade (Apache’s fixed releases are 2.3.20.3, 2.3.24.3 and 2.3.28.1), and disable Dynamic Method Invocation where you cannot upgrade immediately.
4. Strapi: CVE-2023-22894
Product: Strapi headless CMS, versions 3.2.1 up to (not including) 4.8.0, per Strapi’s disclosure. Flaw: filtering on private fields lets attackers with admin-panel access pull sensitive user data, which Strapi says can include email addresses, password hashes and password reset tokens. CISA notes it can be chained with CVE-2023-22621, a template-injection flaw, to reach code execution, and that affected versions may be end-of-life. Added: October 8. Due: October 11. CISA flags it for forensic triage. First action: upgrade to Strapi 4.8.0 or later, then reset admin credentials and password-reset tokens on any instance that was exposed.
5. ONLYOFFICE Docs (Document Server): CVE-2021-3199
Product: ONLYOFFICE Document Server, in setups that use JWT. Flaw: a path traversal through a /.. sequence in an image-upload parameter that CISA says can lead to remote code execution. The Hacker News lists the affected range as 5.1.5 through 5.6.2. Added: October 8. Due: October 11. CISA flags it for forensic triage. First action: upgrade to 5.6.3 or later (the release referenced in CISA’s notes) and review the server for unexpected files.
6. ProFTPD: CVE-2015-3306
Product: ProFTPD 1.3.5 with the mod_copy module. Flaw: the SITE CPFR and SITE CPTO commands let remote attackers read and write arbitrary files without logging in. NVD scores it CVSS v2 10.0. Added: October 8. Due: October 11. CISA flags it for forensic triage. First action: upgrade off 1.3.5 (The Hacker News lists 1.3.5a as the fix) or disable mod_copy, and question why an FTP server is internet-facing at all.
| CVE | Product | Vulnerable | Fixed in | Due |
|---|---|---|---|---|
| CVE-2026-88779 | NetScaler ADC/Gateway (SAML SP/IdP) | 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; FIPS/NDcPP before listed builds | 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282 | Oct 7 (passed) |
| CVE-2015-5477 | ISC BIND | 9.x before 9.9.7-P2; 9.10.x before 9.10.2-P3 | 9.9.7-P2, 9.10.2-P3 or later supported release | Oct 11 |
| CVE-2016-3081 | Apache Struts | 2.3.20–2.3.28 (except 2.3.20.3, 2.3.24.3), DMI on | 2.3.20.3, 2.3.24.3, 2.3.28.1 | Oct 11 |
| CVE-2023-22894 | Strapi | 3.2.1 to before 4.8.0 | 4.8.0 | Oct 11 |
| CVE-2021-3199 | ONLYOFFICE Document Server (JWT) | 5.1.5–5.6.2 (single-source range) | 5.6.3 | Oct 11 |
| CVE-2015-3306 | ProFTPD (mod_copy) | 1.3.5 | 1.3.5a (single-source) | Oct 11 |
The Hacker News checked CISA’s KEV data at 18:05 UTC on October 8 and found none of the five advisory CVEs listed. They showed up in the next catalog release that evening. If your team pulls KEV once a day in the morning, the October 11 clock may have started before your tooling even saw it. For a three-day deadline, that lag can cost you a full day.
Threat Intelligence Breakdown
Attribution, October 8 batch: The joint advisory describes Integrity Technology Group as a China-based for-profit company with links to the Chinese government. The agencies say it acquires or builds cyber tools, hosts infrastructure and compromises victim networks. The observed methods are consistent with activity publicly tracked as Flax Typhoon, Ethereal Panda and RedJuliett, but the advisory cautions that commercial tracking labels may not map one-to-one to the U.S. government’s assessment. The FBI says the evidence came from multiple investigations. Confirmed targeting included U.S. critical infrastructure and organizations across Southeast Asia, Africa and North America; observed email theft affected government, law enforcement, healthcare and religious organizations in Southeast Asia. The advisory does not provide a total victim count.
Attribution, NetScaler: Unknown. Neither Citrix nor CISA has named an actor, and CISA lists ransomware use as unknown for all six entries.
Indicators of compromise (verified against joint advisory AA26-281A; defanged):
| Type | Indicator | Context |
|---|---|---|
| Domain | natcloudservice[.]com | Main command-and-control domain for an email-collection bot (The Hacker News) |
| Domain | dns.studiocloud[.]xyz | Attributed to Integrity Tech; FBI assesses the malware likely targets email (The Hacker News) |
| Domain | c0cc[.]cc | MicroScan infrastructure (BleepingComputer) |
| Domains | 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, linkedinns[.]net | Malware delivery (BleepingComputer) |
| Domain | 98aiblog[.]com | SoftEther VPN remote access (BleepingComputer) |
| Files | live700_v1.exe, fake DiagTrack.exe, DC.exe, Curlc4.txt, office-cli; SoftEther installers renamed conhost.exe or dllhost.exe | Tools named in the advisory (The Hacker News) |
| Behavior | Unexpected Active Directory replication (DCSync); EBurst password spraying against Exchange endpoints | Recommended detection focus |
How to read these: The 58-page advisory includes observed indicators and tool hashes, some tied to activity going back years. Treat the domains as hunting leads in DNS and proxy logs, not as a complete blocklist; validate matches in context before blocking or beginning eviction.
Enterprise Impact: What’s Actually at Risk
Email and identity: The Integrity Tech activity focused on stealing email and Active Directory credentials. A compromised Struts, ProFTPD or ONLYOFFICE host can be the first step toward a domain controller.
Remote access: A SAML-enabled NetScaler that is still unpatched can be crashed on demand, cutting off VPN and SSO.
DNS availability: CVE-2015-5477 can take down an old BIND resolver or authoritative server with one query type.
Customer data: A vulnerable Strapi backend can leak user emails, password hashes and reset tokens, which may trigger breach-notification duties.
Audit and insurance: Six KEV entries in one week, two deadlines, and one already passed. Record when you checked for each product and what you found, including “not present.”
What Security Leaders Should Do Next
Today
- Close NetScaler: confirm every SAML-enabled ADC and Gateway, including HA, DR and FIPS units, is on 14.1-73.41, 13.1-64.28 or the matching FIPS/NDcPP build.
- Search for the five legacy products in asset inventory, software composition data and external attack-surface scans: ProFTPD, Struts 2.3, Strapi, ONLYOFFICE Document Server and BIND.
- Cut exposure first for anything you find on the internet: firewall it, disable
mod_copyor Struts Dynamic Method Invocation, or shut it down until you can upgrade.
Within 48 hours
- Patch or retire everything you found before the October 11 deadline.
- Run compromise checks on the four forensic-triage products (Struts, Strapi, ONLYOFFICE, ProFTPD): unexpected files, new accounts, web shells and outbound connections.
- Hunt the reported domains in DNS and proxy logs, and look for DCSync activity and Exchange password spraying.
Long-term
- Pull KEV more than once a day, or subscribe to CISA’s feed, so a three-day deadline doesn’t lose a day to sync lag.
- Track embedded components, not just products. Four of the five October 8 entries carry CISA’s warning that the flaw may sit inside other vendors’ products.
- Give legacy servers an owner or a retirement date. Old software with no owner is what this week’s list exposed.
Get zero-day alerts before they hit the headlines
DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.
Winners and Losers
| Better positioned | More exposed |
|---|---|
| Teams with software bills of materials that can find a Struts 2.3 jar in minutes | Teams that only scan for products by vendor name |
| Organizations that retired internet-facing FTP years ago | Organizations with orphaned FTP and legacy Java hosts |
| Teams that re-patched NetScaler for SAML before October 7 | Teams that stopped after the PitScaler upgrade |
| SOCs that ingest KEV updates several times a day | Programs that sync KEV once each morning |
Final Executive Takeaway
This week’s KEV list is mostly about software you forgot you had.
One new NetScaler zero-day needed an emergency upgrade. The other five entries are years-old bugs that already have published fixes, and a China-linked operator has been using them anyway. The work is not patch engineering. It is finding the systems.
Confirm NetScaler. Find the five. Patch or unplug them by Sunday.
Frequently Asked Questions
Which vulnerabilities did CISA add to KEV between October 3 and October 9, 2026?
CISA added six exploited vulnerabilities to its Known Exploited Vulnerabilities catalog that week: Citrix NetScaler CVE-2026-88779 on October 4, and ISC BIND CVE-2015-5477, Apache Struts CVE-2016-3081, Strapi CVE-2023-22894, ONLYOFFICE Docs CVE-2021-3199 and ProFTPD CVE-2015-3306 on October 8.
What is the CISA deadline for the October 8, 2026 KEV additions?
The five CVEs CISA added to KEV on October 8, 2026 (CVE-2015-5477, CVE-2016-3081, CVE-2023-22894, CVE-2021-3199 and CVE-2015-3306) are due Sunday, October 11, 2026, for federal civilian agencies. The NetScaler flaw CVE-2026-88779 was due October 7, 2026.
Why did CISA add old vulnerabilities like CVE-2015-3306 and CVE-2016-3081 to KEV in October 2026?
CISA added old flaws including ProFTPD CVE-2015-3306 and Apache Struts CVE-2016-3081 to KEV on October 8, 2026, the same day an FBI-led joint advisory said Integrity Technology Group, a China-linked company tied to Flax Typhoon activity, had exploited them. Being on KEV means CISA has evidence of exploitation, whatever the CVE’s age.
How do I fix the Citrix NetScaler zero-day CVE-2026-88779?
Upgrade NetScaler ADC and Gateway appliances configured as SAML SP or IdP to 14.1-73.41 or 13.1-64.28 or later, or to 14.1-73.41 FIPS or 13.1-37.282 for FIPS and NDcPP builds. Builds installed earlier for the PitScaler flaws, such as 14.1-73.37, are still vulnerable to CVE-2026-88779.
What versions fix Apache Struts CVE-2016-3081?
Apache lists Struts 2.3.20.3, 2.3.24.3 and 2.3.28.1 as fixed for CVE-2016-3081 (S2-032). The flaw affects Struts 2.3.20 through 2.3.28 when Dynamic Method Invocation is enabled, and disabling Dynamic Method Invocation is Apache’s workaround.
Are there indicators of compromise for the Flax Typhoon-linked KEV vulnerabilities?
Yes. Joint advisory AA26-281A includes domains such as natcloudservice[.]com and dns.studiocloud[.]xyz, renamed SoftEther VPN installers, malware and script names, hashes, and DCSync activity. The advisory is 58 pages and provides downloadable STIX files; defenders should validate matches in context before blocking or beginning eviction.
Is ransomware linked to this week’s CISA KEV additions?
CISA lists known ransomware use as “Unknown” for all six CVEs added to KEV between October 3 and 9, 2026, including NetScaler CVE-2026-88779 and the five October 8 entries. The October 8 batch is tied to espionage-style activity by a China-linked company, not to a named ransomware group.
Sources
Primary sources: Joint Cybersecurity Advisory AA26-281A and its official 58-page PDF (published October 8, 2026); CISA Known Exploited Vulnerabilities catalog (catalog version 2026.10.08, cross-checked through CISA’s official kev-data repository); Citrix security bulletin CTX697174; Apache Struts S2-032; Strapi security disclosure; NVD records for CVE-2015-5477 and CVE-2015-3306. Additional reporting reviewed: The Hacker News and BleepingComputer. Reflects public information available October 9, 2026.
