Vendor

ProFTPD

1 known exploited

ProFTPD news

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns

CISA added CVE-2015-3306 (ProFTPD ProFTPD) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Why it matters

CISA lists this as exploited in the wild. Unpatched ProFTPD systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Severity raisedUpdateKEV

    UPDATE: severity raised to critical: ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  2. AdvisoryKEV

    Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

    Basis: CISA Cybersecurity Advisories (government advisory)

  3. AdvisoryKEV

    ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  4. Added to CISA KEVCVE-2015-3306

    CVE-2015-3306 added to CISA KEV: ProFTPD ProFTPD, ProFTPD Improper Access Control Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

Actively exploited

All 1 →
CVE-2015-3306CVSS 10.0

ProFTPD ProFTPD

ProFTPD Improper Access Control Vulnerability

Added Oct 8, 2026Fed. due Oct 11, 2026Coverage →

Products