CISA Orders Federal Agencies to Patch Five Exploited Flaws by October 11 Amid Flax Typhoon Campaign
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch five actively exploited security vulnerabilities by October 11, 2026. These flaws, affecting products like ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081), and ISC BIND (CVE-2015-5477), are being exploited by the China-linked threat actor Flax Typhoon. The directive requires agencies to apply vendor patches or discontinue the use of affected software.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai