The federal cyber defense agency added five high-risk security flaws to its active threat list on October 8, 2026. These actively exploited software vulnerabilities impact popular enterprise tools including Apache Struts, Strapi, ONLYOFFICE, and ProFTPD. Network defenders must apply official vendor patches immediately to block remote network takeovers.
- Total: 5 CVEs
- Severity: 2 Critical Β· 3 High
- Actively exploited: 5 (exploited in the wild)
- Exploit Intel (PatchThis): 5 of 5 confirmed
- Highest severity: 10.0 (Critical Β· CVSSv3) β CVE-2015-3306
- Action: Apply the latest security updates now
Route critical Apache CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status | PoC |
|---|---|---|---|---|
| CVE-2015-3306 | 10 | CWE-284 | Exploited | Available (Metasploit, Nuclei) |
| CVE-2021-3199 | 9.8 | CWE-22 | Exploited | β |
| CVE-2016-3081 | 8.1 | CWE-77 | Exploited | Available (Metasploit, Nuclei) |
| CVE-2015-5477 | 7.5 | CWE-19 | Exploited | Available (Metasploit) |
| CVE-2023-22894 | 7.2 | CWE-312 | Exploited | β |
Why These Flaws Matter
Hackers scan internet-connected networks daily to locate unpatched application servers. These specific flaws grant attackers direct administrative access to internal business networks. A successful intrusion can lead to complete system compromise and severe data theft. Security operations teams rely on the known exploited vulnerabilities catalog to prioritize their emergency patches. Ignoring these critical warnings exposes organizations to immediate ransomware threats.
How the Attacks Work
Each software bug uses a distinct mechanism to bypass security controls. Fixing these actively exploited software vulnerabilities prevents critical remote code execution events. The ONLYOFFICE flaw uses a directory traversal path during image uploads to run commands. The ProFTPD bug allows remote users to copy arbitrary files via specific FTP site commands. The Strapi vulnerability abuses weak API query filters to expose sensitive password hashes.
The Apache Struts weakness forces remote code execution through chained evaluation expressions. This only occurs when dynamic method invocation remains active. Finally, the ISC BIND defect creates a severe denial of service condition. Attackers send malformed TKEY queries that crash the background processing daemon.
Affected Versions and Patch Steps
Network administrators must upgrade all impacted software versions quickly. Strapi installations up to version 4.5.5 need an immediate platform update. ONLYOFFICE Document Server deployments older than version 5.6.3 require patching. Apache Struts 2.3 series users must migrate to the latest secure releases. ISC BIND 9.9 and 9.10 administrators must apply the newest point updates. ProFTPD users running version 1.3.5 require immediate system remediation.
Official sources do not provide exact vulnerable installation counts. However, these actively exploited software vulnerabilities target broadly deployed open-source packages across many industries. Information technology departments must follow official vendor mitigation instructions immediately. If cloud service providers cannot supply mitigations, companies should discontinue using the vulnerable product to prevent exploitation.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!