Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns

CISA added CVE-2015-3306 (ProFTPD ProFTPD) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Excerpt from the primary source: CISA Known Exploited Vulnerabilities

Who is affected

Security professionals

Affected technology: ProFTPD

Why it matters

CISA lists this as exploited in the wild. Unpatched ProFTPD systems are exposed to active attacks now.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Act now

Treat this as an emergency. Identify every system running ProFTPD, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.

CISA's required action for CVE-2015-3306: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines." US federal civilian agencies must comply by October 11, 2026.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns CISA Known Exploited Vulnerabilities · cisa.gov · Oct 8, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

International coalition seizes tools used by cyber firm behind Flax Typhoon

The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.

Severity: ElevatedAction: Be aware

Making sure the checks get printed

Pierre's debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn't an option.

Severity: HighAction: Patch

Cisco Patches a Dozen Critical Vulnerabilities

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

Patch

Apply the vendor's security update for Cisco networking & security.

ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns | CybersecurityNews.us