< BACK TO NEWS
importantSYS.SOURCE: The Hacker News• 2026-10-09T17:51:51+05:30

CISA Adds Five Vulnerabilities to KEV Catalog Amid Flax Typhoon Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked threat actor Flax Typhoon. A deadline of October 11 is set for federal agencies to address these critical security flaws.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.

The vulnerabilities in question are listed below -

CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow

Read original article

*** END OF TRANSMISSION ***