
China-linked Flax Typhoon has been actively exploiting five vulnerabilities — some dating back to 2015 — while CISA set today as the deadline for federal agencies to patch or pull the affected software. On Thursday, the FBI seized two of the group’s primary scanning tools. None of that changes the fact that the CVEs are still open. If you run Strapi, Apache Struts, ProFTPD, BIND, or ONLYOFFICE in production, this applies to you regardless of whether you work for the government.
Who Is Flax Typhoon
Flax Typhoon is a Chinese state-sponsored group operating under Integrity Technology Group, a Beijing contractor for China’s Ministry of State Security. Their targets span universities, tech companies, telecom providers, and media organizations. The goal is not immediate disruption — it’s pre-positioning. They want persistent access to operational technology networks so they can disrupt critical functions at a time of their choosing. The FBI disrupted their MicroScan vulnerability scanner and FishHub spear-phishing platform this week, seizing seven domains in an international operation. MicroScan alone carried over 1,300 penetration testing scripts targeting Oracle WebLogic, Apache Struts, WordPress, Jenkins, and Microsoft Exchange.
The Five CVEs
CISA added all five to its Known Exploited Vulnerabilities (KEV) catalog this week. Federal agencies had until today under Binding Operational Directive 22-01. Private organizations have no mandatory deadline — but if your security insurance policy references KEV, that conversation just became relevant.
| CVE | Product | CVSS | Action Required |
|---|---|---|---|
| CVE-2015-3306 | ProFTPD | 10.0 | Upgrade to 1.3.5a+; disable mod_copy |
| CVE-2016-3081 | Apache Struts | 8.1 | Upgrade to 2.3.28.1+; disable DMI |
| CVE-2021-3199 | ONLYOFFICE Docs | 9.8 | Update to latest patched version |
| CVE-2023-22894 | Strapi | 7.2 | Upgrade to 4.8.0+ |
| CVE-2015-5477 | ISC BIND | 7.5 | Upgrade to 9.9.7-P2 or 9.10.2-P3 |
CVE-2015-3306: ProFTPD (CVSS 10.0)
The mod_copy module in ProFTPD 1.3.5 allows unauthenticated attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. No login required. The practical exploit: copy a PHP payload to the web root, trigger remote code execution. Metasploit has a module for this. Fifteen public proof-of-concept repositories exist. If ProFTPD is running with mod_copy enabled and any web directory is accessible, assume it is compromised. Upgrade to 1.3.5a or later, or remove the LoadModule mod_copy.c line from your config and restart.
CVE-2016-3081: Apache Struts (CVSS 8.1)
When Dynamic Method Invocation is enabled in Apache Struts 2.3.19 through 2.3.28, attackers can pass a method: prefixed parameter that feeds unsanitized input directly into the OGNL evaluation engine — resulting in remote code execution. This is the same class of vulnerability that caused the Equifax breach in 2017. It keeps coming back because large enterprise Java applications run on Struts with nobody touching the framework version. Upgrade to 2.3.28.1, 2.3.24.3, or 2.3.20.3. If you cannot upgrade immediately, set struts.enable.DynamicMethodInvocation = false in struts.xml. Full details are in the Apache Struts S2-032 advisory.
CVE-2021-3199: ONLYOFFICE Docs (CVSS 9.8)
A path traversal flaw in ONLYOFFICE Docs via JWT authentication allows an attacker to upload a malicious image that writes to arbitrary server paths — leading to remote code execution. This affects self-hosted document collaboration setups, including Nextcloud and ownCloud integrations. Update ONLYOFFICE Docs to the latest patched version and review your document server’s network exposure.
CVE-2023-22894: Strapi (CVSS 7.2)
Strapi 3.2.1 through 4.7.x allows users with admin panel access to filter on fields marked private in the schema. This means an attacker with even limited admin access can enumerate password hashes and password reset tokens for all users — including API consumers. With super-admin access, the same query surfaces credentials for every account in the database. The fix is to upgrade to Strapi 4.8.0 or later, as documented in Strapi’s security disclosure. If you are running a JAMstack or Next.js application with a Strapi backend and have not checked this, check it today. Strapi has over 65,000 GitHub stars — a lot of production deployments are sitting on vulnerable versions.
CVE-2015-5477: ISC BIND (CVSS 7.5)
A crafted TKEY query causes named to exit with a REQUIRE assertion failure. One packet, one DNS outage. BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are affected. There is no workaround — you must patch. See the ISC security advisory for full details. If you are running self-hosted DNS on BIND 9.9, upgrade to 9.9.7-P2 or later.
How They Chain These Together
Flax Typhoon’s playbook is less sophisticated than most APT coverage implies. MicroScan runs 1,300 scripts against internet-facing services. When ProFTPD or Struts yields initial access, they drop persistence tools — typically VPN software — and begin credential harvesting. Strapi’s CVE-2023-22894 is particularly useful here: admin panel credentials from an initial compromise let attackers quietly enumerate every user’s password hash without triggering alerts. Those hashes get cracked offline and used to pivot into other services. Meanwhile, a single TKEY packet brings BIND down, disrupting DNS resolution across the network.
The Real Problem Is Patch Debt
The oldest CVE on this list is eleven years old. Flax Typhoon is not running a sophisticated zero-day operation — they are running a script against systems nobody has reviewed in years. ProFTPD ships in legacy Linux distributions as a default FTP option. BIND 9.9 runs on nameservers that have been live since 2015 without incident. Apache Struts 2.3.x powers enterprise Java applications where “if it ain’t broke, don’t touch it” passes for a maintenance strategy. Strapi 4.7.x is widely deployed by teams that treat their headless CMS as infrastructure rather than software with a patch cycle.
The FBI seizing MicroScan removes one tool. It does not patch your ProFTPD. Run an inventory of these five products in your environment. Internet-facing instances are the priority. Patch, upgrade, or disable services that are no longer needed. Three additional CVEs already on the KEV list — Shellshock (CVE-2014-6278), Pulse Secure (CVE-2019-11510), and GitLab RCE (CVE-2021-22205) — were also part of this campaign. If any of those apply to your stack, they are overdue.













