CISA adds five old BIND, Struts, Strapi, ONLYOFFICE and ProFTPD flaws to its exploited list
The US cyber agency says it has evidence that long-patched bugs dating from 2015 to 2023 are being exploited, and set a deadline three days after the listing.

Key points
- 1CISA added five previously patched flaws to its catalog of known exploited vulnerabilities this week, citing evidence of active exploitation.
- 2Affected products: ISC BIND, Apache Struts, Strapi, ONLYOFFICE Docs and ProFTPD, with bugs dating from 2015, 2016, 2021 and 2023.
- 3The catalog does not name attackers or give attack dates, and lists ransomware use as unknown for all five.
- 4CISA set a deadline three days after the listing and refers to its BOD 26-04 directive for remediation.
- 5CISA notes the Strapi flaw can be chained with CVE-2023-22621 for remote code execution and that affected versions may be end-of-life.
Full story
The US agency CISA added five vulnerabilities to its catalog of Known Exploited Vulnerabilities this week. None of them is new: they affect ISC BIND (CVE-2015-5477), Apache Struts (CVE-2016-3081), Strapi (CVE-2023-22894), ONLYOFFICE Docs (CVE-2021-3199) and ProFTPD (CVE-2015-3306). A listing in the catalog means CISA has evidence of exploitation in the wild, but the entries do not name any attacker or say when the attacks took place.
According to the catalog, the BIND bug lets remote attackers make BIND servers exit with crafted TKEY queries, causing a denial of service. The Struts flaw is a command injection issue that can lead to remote code execution through the method: prefix when Dynamic Method Invocation is switched on. The ProFTPD entry describes an access control weakness that could allow remote attackers to read and write arbitrary files using the site cpfr and site cpto commands.
For Strapi, CISA describes cleartext storage of sensitive information that lets someone with admin panel access uncover user details through the query filter; the agency adds that it can be chained with CVE-2023-22621 for remote code execution and that affected versions may be end-of-life. The ONLYOFFICE Docs flaw is a path traversal in an image upload parameter that arises when JWT is in use and could also enable remote code execution. CISA lists ransomware use as unknown for all five entries.
The fixes are old. ISC published its advisory on 28 July 2015 with patched releases 9.9.7-P2 and 9.10.2-P3, and at the time said it knew of no active exploits. The Apache Struts bulletin S2-032 covers versions 2.3.20 to 2.3.28, apart from 2.3.20.3 and 2.3.24.3, and lists 2.3.28.1, 2.3.24.3 and 2.3.20.3 as fixed releases; turning off Dynamic Method Invocation is the alternative. CISA set a deadline three days after the listing for all five and points to its BOD 26-04 directive, telling users to apply vendor mitigations or stop using the product if none are available.
Why it matters
Attackers keep returning to old bugs because outdated, unpatched or end-of-life systems often stay online for years. Organisations running BIND, Struts, Strapi, ONLYOFFICE Docs or ProFTPD should check their inventories for exposed older versions, apply the vendor fixes, and retire or isolate systems that can no longer be updated, as CISA advises.
Timeline
· Published
Topics#CISA#KEV#Apache Struts#ISC BIND#Strapi#ProFTPD
Sources
This story draws on the following sources. Read them for full context.



