Exploited vulnerabilities put files, apps and DNS at risk
Imazh i krijuar me IA

Exploited vulnerabilities put files, apps and DNS at risk

Five exploited vulnerabilities join CISA's catalog, with risks including file access, code execution and DNS disruption; federal fixes are due October 11.

Exploited vulnerabilities affecting file transfers, document editing, content management, web applications and DNS have been added to a federal security catalog, according to The Hacker News. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, a list of security weaknesses that attackers have used in real attacks. Federal agencies must apply the necessary patches or stop using the affected software by October 11, 2026.

The additions concern ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts and ISC BIND. For website owners and IT teams, the important distinction is that these are not merely theoretical weaknesses. The catalog records exploitation, although inclusion does not establish that any particular installation has been compromised. The supplied report does not identify fixed software versions, give installation-specific checks or quantify how many systems have been affected.

The ProFTPD issue, CVE-2015-3306, has a Common Vulnerability Scoring System (CVSS) score of 10.0. CVSS expresses vulnerability severity on a scale ending at 10, rather than measuring how many attacks have occurred. The flaw involves improper access control, meaning the software does not correctly restrict an operation. A remote attacker could use the site cpfr and site cpto commands to read and write arbitrary files. For a hosting environment, this makes file access and modification the central concern, not simply the availability of the file-transfer service.

CVE-2021-3199 affects ONLYOFFICE Docs and carries a CVSS score of 9.8. It is a path traversal vulnerability, in which manipulated file paths can reach outside their intended location. The report describes it as occurring when JSON Web Token (JWT), a token format used to pass identity or access information, is used. A "/.." sequence in an image-upload parameter, a value submitted with the upload, could enable remote code execution. That means an attacker could cause the affected system to run code, rather than only upload an image. The report does not provide enough configuration detail to determine exposure for an individual deployment.

The Strapi vulnerability, CVE-2023-22894, has a CVSS score of 7.2 and concerns sensitive information stored in cleartext, meaning without encryption. An attacker who already has access to the administration panel could discover sensitive user details through the query filter, the facility for narrowing requested information. That access requirement matters: the description is not evidence that an unauthenticated visitor can retrieve those details directly. Teams managing content through Strapi should distinguish this information-disclosure risk from the remote code execution issues elsewhere in the catalog additions.

Apache Struts is affected by CVE-2016-3081, rated 8.1. This is command injection, where attacker-controlled input is treated as an instruction to execute. The report says a remote attacker could run arbitrary code through method:prefix when Dynamic Method Invocation is enabled. That feature allows an application to select methods dynamically, so its enabled state is a relevant condition in the reported attack mechanism. The source does not name a corrected release or establish whether a particular application uses that configuration.

The fifth addition, CVE-2015-5477, affects ISC BIND and has a CVSS score of 7.5. BIND provides Domain Name System (DNS) services, which help computers find the addresses associated with domain names. The vulnerability is a reachable assertion: specially handled input can reach an internal software check that causes the process to stop. A remote attacker could trigger denial-of-service, making the service unavailable, through TKEY queries, requests associated with DNS key establishment. Its reported consequence is disruption, not the file access or code execution described for other flaws in this group.

According to The Hacker News, a joint advisory accompanying the additions describes exploitation of eight vulnerabilities for initial access to organisations and theft of sensitive data. The other three were already in KEV: CVE-2014-6278, the GNU Bash command-injection flaw associated with Shellshock, added in October 2025; CVE-2019-11510, an arbitrary-file-read flaw in Ivanti Pulse Connect Secure, added in November 2021; and CVE-2021-22205, a remote code execution flaw in GitLab Community and Enterprise Edition, also added in November 2021.

The technical activity described includes scanning tools that look for exposed systems, cross-site scripting that runs malicious content in a browser, and password spraying against Microsoft Exchange servers, where attackers try commonly used passwords across accounts. The advisory also describes continued access through virtual private network (VPN) software, which provides a network connection through an encrypted tunnel, and scripts used to steal emails and credentials, such as login details.

For businesses outside the federal deadline, these exploited vulnerabilities warrant a concrete software inventory and a conversation with whoever maintains the affected services. Website owners may need their hosting provider or IT administrator to establish whether the software is present, whether the stated conditions apply and which vendor-supported update is appropriate. The October 11 requirement is a federal obligation, not a universal deadline for every website. Nor does this report establish that an update alone would remove access an attacker had already obtained.

Si të Mbroheni

  1. Send the affected software names and vulnerability identifiers to your hosting provider or IT support team and ask whether your services use them.
  2. Ask your service administrator to confirm that the affected software has received the appropriate vendor security updates.
  3. If you manage Strapi, review who can access its administration panel and remove accounts that no longer need access.
  4. Use a unique password for your work email account and turn on multifactor authentication, which adds an extra sign-in check.
  5. Ask your provider whether any affected service that cannot be updated should be taken offline until it can be secured.

Dobësitë & Zgjidhjet

Termat e Shpjeguar

  • Known Exploited Vulnerabilities A catalog of software weaknesses that attackers have already used in real attacks.
  • CVSS The Common Vulnerability Scoring System rates the severity of a software weakness on a scale ending at 10.
  • path traversal A flaw that lets manipulated file locations reach files outside the area intended by the software.
  • remote code execution The ability to make another computer run attacker-chosen instructions over a network.
  • DNS The Domain Name System helps computers find the addresses associated with names of websites and other internet services.
  • denial-of-service An attack that makes a service unavailable to the people who need it.
  • password spraying Trying a small set of common passwords against many accounts to find one that allows access.
  • VPN A virtual private network carries a network connection through an encrypted tunnel.

Shërbime AEU të lidhura

  • AEU DNS Resolver DNS i enkriptuar