ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns
CISA added CVE-2015-3306 (ProFTPD ProFTPD) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CISA lists this as exploited in the wild. Unpatched ProFTPD systems are exposed to active attacks now.
Treat this as an emergency.
