FORSMILE
JA
セキュリティ2026/10/09

ProFTPD CVE-2015-3306 and 4 Other Old Flaws Added to CISA KEV: Check for Old Struts, BIND, Strapi and ONLYOFFICE Too — ProFTPD Allows Unauthenticated File Access

On 8 October 2026 CISA added five vulnerabilities published between 2015 and 2023 (ProFTPD, Apache Struts, ISC BIND, Strapi and ONLYOFFICE Docs) to its Known Exploited Vulnerabilities catalog. Fixes have existed for years, so this is not about a new hole but about old versions still running. Inventory your servers for these products and update to the fixed versions.

← Back to Blog

On 8 October 2026 CISA added five vulnerabilities, published 3 to 11 years ago, to its Known Exploited Vulnerabilities (KEV) catalog: ProFTPD (CVE-2015-3306), Apache Struts (CVE-2016-3081), ISC BIND (CVE-2015-5477), Strapi (CVE-2023-22894) and ONLYOFFICE Docs (CVE-2021-3199).
Fixes for all five have existed for a long time. This is not about a new hole; it is about whether an old version is still running somewhere.

KEV listing means exploitation has been confirmed. But who is exploiting it, where and since when is not written in the KEV entries. The remediation deadline for all five is 11 October, but that is a deadline for US federal agencies, not a legal deadline for organisations in Japan. Rather than watching the deadline, check today whether an old version is still on your servers.

⚠ CVE Score — 最高危険度 / CRITICAL
10CRITICALCVSS v3.1CVE-2015-3306

The score shown is for ProFTPD CVE-2015-3306, the highest of the five. The NVD page carries both NIST's own rating (CVSS v2.0 10.0, HIGH) and CISA's rating (CVSS v3.1 10.0, CRITICAL). This article shows CISA's v3.1 value (10.0). NVD still lists this CVE as "Undergoing Analysis".

What to do now

  • ✓First, inventory the servers you manage for the five products below. If you run an FTP server (ProFTPD), a Java business system (Struts), a DNS server (BIND), a headless CMS (Strapi) or collaborative document editing (ONLYOFFICE), you are in scope.
  • ✓If you run ProFTPD, check the version. NVD lists 1.3.5 as affected, and ProFTPD's NEWS file records Bug 4169 as fixed in 1.3.6rc1, and an openSUSE update notice records the fix in 1.3.5a. If you are still on 1.3.5, update.
  • ✓If you run Apache Struts 2, check which of the fixed versions Apache names (2.3.20.3, 2.3.24.3, 2.3.28.1) applies to you. It cannot be read as a single "or later": for example 2.3.21 has a higher number than 2.3.20.3 but is inside the affected range. Move to the fixed version for your release line (2.3.20.3 for 2.3.20.x, 2.3.24.3 for 2.3.24.x, 2.3.28.1 for 2.3.28.x), or to a safe version you have confirmed in the Apache advisory. Apache's advisory (S2-032) says to upgrade to the fixed versions. Until you can, Apache lists disabling Dynamic Method Invocation as a workaround.
  • ✓If you run BIND 9, check that you are on 9.9.7-P2 or later (9.9 line) or 9.10.2-P3 or later (9.10 line). ISC states that there is no workaround for this flaw.
  • ✓If you run Strapi, check that you are on 4.8.0 or later. Strapi's disclosure says CVE-2023-22894 affects 3.2.1 up to but not including 4.8.0 and was fixed in 4.8.0; the chained CVE-2023-22621 (RCE) was fixed in 4.5.6. KEV notes the product may be end-of-life, so if you are on an old line, also consider moving to a supported version.
  • ✓If you run ONLYOFFICE Docs (Document Server), check that you are on 5.6.3 or later. ONLYOFFICE's changelog lists, under 5.6.3, a fix for path traversal via image upload parameters.
  • ✓★Even after updating, look for signs of compromise. Updating does not undo an intrusion that already happened. Check for unfamiliar processes, files you do not recognise, changes to administrator accounts or API tokens, and anomalies in logs (this is general advice from this site, not a vendor procedure).
  • ✓Keep old systems you cannot update off the direct internet (do not expose admin panels or FTP; put them behind a VPN). This is also general advice from this site.

The five at a glance

  • ▸ProFTPD CVE-2015-3306 (published in NVD 18 May 2015): the SITE CPFR / SITE CPTO commands in the mod_copy module let a remote attacker read and write arbitrary files. NVD's rating shows no authentication required. NVD lists 1.3.5 as affected; the fix is in 1.3.5a / 1.3.6rc1
  • ▸Apache Struts CVE-2016-3081 (26 April 2016): with Dynamic Method Invocation enabled, arbitrary code can be executed via the `method:` prefix. Apache's advisory lists 2.3.20 to 2.3.28 (except 2.3.20.3 and 2.3.24.3) as affected, fixed in 2.3.20.3 / 2.3.24.3 / 2.3.28.1. NVD rates it v3.0 8.1 (HIGH)
  • ▸ISC BIND CVE-2015-5477 (29 July 2015): a TKEY query makes named exit (denial of service). ISC lists BIND 9.1.0 through 9.9.7-P1 and 9.10.2-P2 as affected, fixed in 9.9.7-P2 / 9.10.2-P3, no workaround. CISA rates it v3.1 7.5 (HIGH)
  • ▸Strapi CVE-2023-22894 (19 April 2023): an attacker with admin-panel access can use the query filter to infer sensitive user information. With super-admin access, NVD says this reaches every user's password hash and password-reset token. KEV says it chains with CVE-2023-22621 to reach RCE. The ratings differ: NVD v3.1 4.9 (MEDIUM), CISA 7.2 (HIGH)
  • ▸ONLYOFFICE Docs CVE-2021-3199 (26 January 2021): when JWT is used, directory traversal via an image-upload parameter on /upload can lead to remote code execution. Affected: before 5.6.3. NVD rates it v3.1 9.8 (CRITICAL, no authentication)

What happened (with dates)

  • ▸May 2015 to April 2016: the ProFTPD, BIND and Struts flaws were each disclosed (BIND in July 2015, Struts in April 2016)
  • ▸January 2021 and April 2023: the ONLYOFFICE Docs and Strapi flaws were disclosed
  • ▸★8 October 2026: CISA added all five to KEV. The deadline is 11 October (for US federal agencies). The KEV entries do not describe how they were exploited or how widely

What could not be confirmed

  • ▸Why these old flaws were added to KEV now. CISA's entries say only that exploitation was confirmed, and do not say when, by whom or at what scale. I did not look into damage in Japan and have not confirmed any
  • ▸The affected range for CVE-2015-3306. NVD's configuration lists only 1.3.5. Whether earlier versions are affected cannot be told from NVD (the only thing confirmed is that the fix is recorded as 1.3.5a / 1.3.6rc1)
  • ▸Differences in the Struts affected range. Apache's advisory says 2.3.20 to 2.3.28, NVD's description starts at 2.3.19, and NVD's configuration (CPE) lists 57 entries including the much older 2.0.0 line. This article mainly follows Apache, the vendor, but if you run an old line you need to update either way
  • ▸Differences in the Strapi affected range. NVD's description says "through 4.5.5", while NVD's configuration and Strapi's disclosure say "before 4.8.0". This article follows the vendor (Strapi): before 4.8.0
  • ▸ProFTPD and Strapi are still "Undergoing Analysis" in NVD, so NVD's ratings for them may change
  • ▸Where the ONLYOFFICE fix stands. The changelog confirms a fix was added in 5.6.3; I did not confirm that later versions are completely closed

Three lines to share

  • ▸On 8 October CISA added five old vulnerabilities (2015 to 2023) in ProFTPD, Struts, BIND, Strapi and ONLYOFFICE Docs to KEV as confirmed-exploited. This is not a new hole; it is about old versions still running
  • ▸★Inventory your servers for these five products. If you run them, update to ProFTPD 1.3.5a or later, Struts 2 the fixed version Apache names for your release line (2.3.20.3 / 2.3.24.3 / 2.3.28.1), BIND 9.9.7-P2 or later on the 9.9 line / 9.10.2-P3 or later on the 9.10 line, Strapi 4.8.0 or later, ONLYOFFICE 5.6.3 or later
  • ▸After updating, still check for unfamiliar processes, files and administrator changes. Keep anything you cannot update off the direct internet

Sources

参考リンク / References
Related articles