CISA Adds Five Flaws Exploited by Flax Typhoon
π‘οΈ CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after a China-linked actor called Flax Typhoon abused them to gain access and exfiltrate data. The flaws span ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND with CVSS scores from 7.2 to 10.0. A joint advisory from multiple nations links the activity to a China-based company, and federal agencies must patch or discontinue affected systems by October 11, 2026.
