Science & Tech · Cybersecurity · 11 hrs ago
CISA adds five exploited software flaws to its vulnerability catalog
The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, added five software vulnerabilities to its Known Exploited Vulnerabilities catalog.
The flaws affect ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND.
Some could let attackers access or change files, run code or disrupt a service.
CISA links the flaws to cyber operations attributed to China-linked actors associated with Integrity Technology Group.
A joint advisory from seven countries also warned about related activity, which included attempts to break into networks and steal sensitive information.
Under a U.S. directive, federal agencies must fix the listed flaws by October 11, 2026.
CISA also recommends that private organizations review the catalog and address vulnerabilities in their systems.
CISA added five exploited software vulnerabilities to its Known Exploited Vulnerabilities catalog.
The flaws affect ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND.
The vulnerabilities are linked to cyber operations attributed to China-linked actors associated with Integrity Technology Group.
The activity reportedly involved exploiting eight vulnerabilities to access targeted networks and steal sensitive information.
Federal agencies must address the listed flaws by October 11, 2026.
- Who
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA).
- What
- It added five software vulnerabilities to its Known Exploited Vulnerabilities catalog.
- When
- The article was published on October 11, 2026.
- Where
- The affected software is used in computer systems; specific locations of the affected systems are not stated.
- Why
- The flaws were identified as exploited vulnerabilities, and the activity reportedly involved attacks on targeted networks.
This story does not have two clearly opposing sides.
No direct quotes in the coverage so far.
This story does not have a timeline yet.
- Catalog
- CISA Known Exploited Vulnerabilities (KEV)
- Affected software
- ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND
- Vulnerability count
- Five
- Reported campaign
- Activity reportedly exploited eight vulnerabilities
- Federal agency deadline
- October 11, 2026











