Science & Tech · Cybersecurity · 11 hrs ago

CISA adds five exploited software flaws to its vulnerability catalog

CISA adds five exploited software flaws to its vulnerability catalog

The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, added five software vulnerabilities to its Known Exploited Vulnerabilities catalog.

The flaws affect ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND.

Some could let attackers access or change files, run code or disrupt a service.

CISA links the flaws to cyber operations attributed to China-linked actors associated with Integrity Technology Group.

A joint advisory from seven countries also warned about related activity, which included attempts to break into networks and steal sensitive information.

Under a U.S. directive, federal agencies must fix the listed flaws by October 11, 2026.

CISA also recommends that private organizations review the catalog and address vulnerabilities in their systems.

Sources

Related news