Product

Docs

Made by ONLYOFFICE. 1 of its vulnerabilities are known to have been exploited.

Coverage

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

ONLYOFFICE Docs Server Path Traversal Vulnerability (CVE-2021-3199) is being actively exploited, CISA warns

CISA added CVE-2021-3199 (ONLYOFFICE Docs) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

Why it matters

CISA lists this as exploited in the wild. Unpatched Docs systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Severity raisedUpdateKEV

    UPDATE: severity raised to critical: ONLYOFFICE Docs Server Path Traversal Vulnerability (CVE-2021-3199) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  2. AdvisoryKEV

    Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

    Basis: CISA Cybersecurity Advisories (government advisory)

  3. AdvisoryKEV

    ONLYOFFICE Docs Server Path Traversal Vulnerability (CVE-2021-3199) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  4. Added to CISA KEVCVE-2021-3199

    CVE-2021-3199 added to CISA KEV: ONLYOFFICE Docs, ONLYOFFICE Docs Server Path Traversal Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

Actively exploited

ONLYOFFICE Docs

ONLYOFFICE Docs Server Path Traversal Vulnerability

Added Oct 8, 2026Fed. due Oct 11, 2026Coverage →