Back to Intelligence

CISA KEV Alert: Five Actively Exploited Flaws in ProFTPD, Apache Struts, Strapi, ONLYOFFICE Docs, and ISC BIND — Detection and Remediation Guide

SA
Security Arsenal Team
October 11, 2026
10 min read

CISA has added five vulnerabilities affecting ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to its Known Exploited Vulnerabilities (KEV) catalog. A KEV listing is not a theoretical risk score — it is confirmation that threat actors are exploiting these flaws in the wild against real targets. If any of these products are reachable in your environment — and ProFTPD and BIND in particular are everywhere in Linux infrastructure — treat this as a patch-and-hunt event, not a routine advisory.

This post breaks down what the listing means operationally, how to detect post-exploitation behavior across all five products, and how to verify remediation.

What CISA's KEV Addition Actually Signals

The KEV catalog exists for one reason: to cut through CVSS noise and tell defenders which bugs are being weaponized right now. Five additions in a single update, spanning file transfer, DNS, collaboration software, headless CMS, and a Java web framework, is a notable batch. The common thread is internet-facing services with a history of remote code execution and wide deployment.

For Federal Civilian Executive Branch (FCEB) agencies, KEV additions carry a binding remediation deadline under CISA's Binding Operational Directive 22-01 — typically three weeks for non-zero-day additions. For everyone else, the deadline is functionally the same: KEV-listed flaws are routinely folded into ransomware affiliate playbooks and initial-access broker tooling within days of public listing.

Technical Analysis

Affected Products at a Glance

ProductRoleTypical Exposure
ProFTPDFTP/SFTP daemonTCP/21 (often TCP/990, 2222) exposed for file transfer
ISC BIND (named)DNS resolver/authoritative serverTCP/UDP 53 — universally exposed
Apache StrutsJava MVC web frameworkEmbedded in Java web apps behind Tomcat on TCP/8080/8443/443
StrapiNode.js headless CMSAdmin/API panels on TCP/1337 and via reverse proxy
ONLYOFFICE DocsDocument collaboration serverDocument Server on TCP/80/443/8000, often integrated with Nextcloud/ownCloud

Specific affected version ranges and CVE identifiers are published on each vulnerability's KEV entry at cisa.gov/known-exploited-vulnerabilities-catalog. Pull the exact CVEs and due dates from the catalog before scoping your patch effort — do not guess.

Why This Mix Matters

These five products map to two distinct exploitation patterns defenders should plan around:

  1. Memory corruption / protocol-level flaws (ProFTPD, ISC BIND). These daemons run as long-lived services with broad network reachability. Post-exploitation, the tell is the daemon (proftpd, named) spawning child processes — shells, downloaders, tunneling tools — that it has no business spawning.
  2. Web application RCE (Apache Struts, Strapi, ONLYOFFICE Docs). Struts in particular has a long history of server-side injection flaws where exploitation culminates in the JVM executing operating system commands. Strapi and ONLYOFFICE run on Node.js/Java service stacks where successful exploitation produces the same observable artifact: the web service process spawning bash, sh, curl, wget, or writing executable content to /tmp, /dev/shm, or web-accessible directories.

The defenders' advantage: regardless of the specific injection vector, all five exploitation paths converge on abnormal child-process behavior and unexpected file drops. That is where detection engineering effort should go.

Exploitation Status

All five vulnerabilities carry confirmed in-the-wild exploitation — that is the entry requirement for the KEV catalog. Assume internet-facing instances are already being scanned and targeted. Internet-wide scanning against newly listed KEV entries is measurable within hours of publication, and these product classes are staples of botnet and initial-access broker automation.

Detection & Response

Because all five products are predominantly Linux-based services, detection engineering should focus on process lineage (daemon → shell/downloader), suspicious file writes to temp/web directories, and egress connections from service accounts. Syslog and auditd telemetry forwarded into Sentinel gives you cross-platform coverage.

YAML
---
title: ProFTPD or BIND Daemon Spawning Shell or Downloader
id: 3f8a1c52-7b2e-4d91-ae64-9c0d5e7f1234
status: experimental
description: Detects proftpd or named spawning shell interpreters or download tools, a strong post-exploitation indicator for RCE flaws in these daemons (CISA KEV additions).
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  - https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/02/09
tags:
  - attack.execution
  - attack.t1059.004
  - attack.exploitation_remote_services
  - attack.t1210
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/proftpd'
      - '/named'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/zsh'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/python'
      - '/python3'
      - '/perl'
      - '/base64'
  condition: selection_parent and selection_child
falsepositives:
  - Rare: BIND dynamic update hooks or custom ProFTPD ExecOnEvent scripts — baseline and allowlist known admin scripts
level: critical
---
title: Java or Node Web Service Spawning Suspicious Child Processes
id: 8d2e4a17-5f63-4c89-bd21-7a1e3f905c46
status: experimental
description: Detects java (Apache Struts/Tomcat) or node (Strapi, ONLYOFFICE Docs) processes spawning shells, downloaders, or encoding utilities — consistent with web application RCE post-exploitation per CISA KEV additions.
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  - https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/02/09
tags:
  - attack.initial_access
  - attack.t1190
  - attack.execution
  - attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/java'
      - '/node'
      - '/nodejs'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/curl'
      - '/wget'
      - '/base64'
      - '/nc'
      - '/ncat'
      - '/chmod'
      - '/openssl'
      - '/socat'
      - '/php'
  condition: selection_parent and selection_child
falsepositives:
  - Build/deploy pipelines executing npm or Maven lifecycle hooks on build servers — scope to production runtime hosts
level: high
---
title: Executable File Dropped in Temp or Shared Memory by Service Account
id: 1b6c9d04-3e72-4a58-9f47-2d8c6b51e790
status: experimental
description: Detects creation of executable files in /tmp, /var/tmp, or /dev/shm by web/DNS/FTP service users — a common payload-staging step after exploitation of the KEV-listed ProFTPD, Struts, Strapi, ONLYOFFICE, or BIND flaws.
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/02/09
tags:
  - attack.command_and_control
  - attack.t1105
  - attack.defense_evasion
  - attack.t1036
logsource:
  category: file_event
  product: linux
detection:
  selection_path:
    TargetFilename|startswith:
      - '/tmp/'
      - '/var/tmp/'
      - '/dev/shm/'
  selection_user:
    User:
      - 'www-data'
      - 'apache'
      - 'nginx'
      - 'tomcat'
      - 'strapi'
      - 'onlyoffice'
      - 'ds'
      - 'named'
      - 'bind'
      - 'proftpd'
      - 'nobody'
  filter_legit:
    TargetFilename|endswith:
      - '.tmp'
      - '.lock'
      - '.pid'
      - '.sock'
      - '.log'
  condition: selection_path and selection_user and not filter_legit
falsepositives:
  - Application caches and session handlers writing temp files — tune per application after a 7-day baseline
level: high
KQL — Microsoft Sentinel / Defender
// Hunt: shells or download tools spawned by ProFTPD, BIND, Java, or Node services
// Requires Linux Syslog/auditd ingestion (CEF or AMA) into Sentinel
let svcParents = dynamic(["proftpd", "named", "java", "node", "nodejs"]);
let susChildren = dynamic(["sh", "bash", "dash", "curl", "wget", "nc", "ncat", "base64", "perl", "python", "python3", "socat", "openssl", "chmod"]);
Syslog
| where TimeGenerated > ago(14d)
| where ProcessName in~ (svcParents)
   or SyslogMessage has_any (svcParents)
| where SyslogMessage has_any (susChildren)
| extend SuspiciousChild = extract(@"(\b(?:sh|bash|curl|wget|nc|ncat|base64|perl|python3?|socat|openssl)\b)", 1, SyslogMessage)
| where isnotempty(SuspiciousChild)
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), Events = count(), SampleCommand = any(SyslogMessage)
  by Computer, ProcessName, SuspiciousChild
| order by LastSeen desc;
// Companion hunt: egress connections from web/DNS/FTP service accounts to rare external IPs
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessAccountName in~ ("www-data", "apache", "tomcat", "strapi", "onlyoffice", "named", "bind", "nobody", "proftpd")
| where RemoteIPType == "Public"
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
  by DeviceName, InitiatingProcessName, RemoteIP, RemotePort
| where Connections < 50   // rare egress — high-volume destinations are usually legit update/CDN traffic
| order by Connections asc;
VQL — Velociraptor
-- Hunt for shells/downloaders spawned by KEV-affected daemons (proftpd, named, java, node)
-- Deploy across Linux estate via Velociraptor hunt; flag any service-process lineage anomalies
LET svc_parents = `(?i)(proftpd|named|java|node|nodejs)$`
LET sus_children = `(?i)/(sh|bash|dash|curl|wget|nc|ncat|base64|perl|python3?|socat|openssl)$`

SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ svc_parents

-- Correlate children of service parents
SELECT c.Pid AS ChildPid, c.Name AS ChildName, c.Exe AS ChildExe,
       c.CommandLine AS ChildCmdline, c.Username AS ChildUser,
       p.Pid AS ParentPid, p.Name AS ParentName, p.Exe AS ParentExe,
       c.CreateTime AS ChildStart
FROM pslist() AS c, pslist() AS p
WHERE c.Ppid = p.Pid
  AND p.Exe =~ svc_parents
  AND c.Exe =~ sus_children

-- Review staging directories for dropped payloads
SELECT FullPath, Size, Mtime, Mode.String AS Permissions
FROM glob(globs=['/tmp/*', '/var/tmp/*', '/dev/shm/*'])
WHERE Mode.String =~ 'x'
  AND Mtime > now() - 1209600
ORDER BY Mtime DESC
Bash / Shell
#!/bin/bash
# kev-audit.sh — Verify exposure and remediation status for the five KEV-listed products
# Run as root on each Linux host; review output before remediating.
set -u
echo "=== [1] Installed / running versions ==="
if command -v proftpd >/dev/null 2>&1; then proftpd -v 2>/dev/null || proftpd --version; echo "  [!] ProFTPD present — compare version against the CISA KEV entry and vendor advisory"; fi
if command -v named >/dev/null 2>&1; then named -v; echo "  [!] BIND present — check ISC advisory for the fixed release train"; fi
if command -v java >/dev/null 2>&1; then echo "  [*] Java present — enumerate Struts usage:"; find /opt /srv /var/lib/tomcat* /usr/share -name 'struts2-core-*.jar' 2>/dev/null | head -20; fi
if command -v node >/dev/null 2>&1; then echo "  [*] Node present — check for Strapi/ONLYOFFICE deployments:"; find / -maxdepth 6 \( -name 'package.json' -path '*strapi*' -o -path '*onlyoffice*' -o -path '*documentserver*' \) 2>/dev/null | head -10; fi

echo "=== [2] Listening services on expected ports ==="
ss -tlnp 2>/dev/null | grep -E ':(21|53|1337|8000|8080|8443)\b' || echo "  [+] No expected service ports listening"

echo "=== [3] Post-exploitation indicators: service-spawned shells (last 7 days, auditd/syslog) ==="
( ausearch -ts recent -k exec 2>/dev/null; grep -hE '(proftpd|named|java|node).*(/bin/(sh|bash)|curl|wget|nc |base64)' /var/log/syslog /var/log/messages /var/log/auth.log 2>/dev/null ) | tail -30 || true

echo "=== [4] Suspicious executables in staging dirs ==="
find /tmp /var/tmp /dev/shm -type f -perm -u+x -mtime -14 2>/dev/null | grep -vE 'systemd-private' | head -30

echo "=== [5] Remediation actions (uncomment after review) ==="
# Debian/Ubuntu:
# apt-get update && apt-get install --only-upgrade proftpd-basic proftpd-dfsg bind9 bind9utils
# RHEL/Rocky:
# dnf update proftpd bind bind-utils
# Struts:    upgrade struts2-core to the fixed version in the Apache advisory; rebuild and redeploy WARs
# Strapi:    npm install strapi@<fixed-version> && npm run build && restart service
# ONLYOFFICE: upgrade Document Server to the fixed release per onlyoffice.com advisory
# Interim mitigations (if patching is delayed):
#   - Restrict FTP/DNS/CMS ports via firewall to known source ranges:
#     iptables -A INPUT -p tcp --dport 21   -s <trusted-cidr> -j ACCEPT
#     iptables -A INPUT -p tcp --dport 1337 -s <trusted-cidr> -j ACCEPT
#   - Place Strapi admin and ONLYOFFICE Document Server behind VPN/SSO-aware reverse proxy
#   - Disable ProFTPD mod_copy / unused modules; run daemons under dedicated unprivileged users
echo "Done. Cross-check findings against https://www.cisa.gov/known-exploited-vulnerabilities-catalog"

Remediation

  1. Inventory first, patch fast. Pull the five KEV entries from the CISA KEV catalog and record the exact CVE, affected versions, and federal remediation due date for each. Scan your estate — internal and external — for the five products. Don't forget embedded instances: Struts ships inside third-party Java appliances, and ONLYOFFICE Document Server is commonly bundled with Nextcloud/ownCloud deployments.
  2. Apply vendor fixes. Upgrade each product to the fixed release cited in its vendor advisory (Apache, ISC, ProFTPD project, Strapi, and ONLYOFFICE respectively). For Struts, a library-only bump is insufficient — rebuild and redeploy the application artifact and restart the servlet container.
  3. Meet the KEV deadline. FCEB agencies must remediate by the BOD 22-01 due date. Private-sector teams should adopt the same three-week window as an internal SLA — faster for internet-facing instances.
  4. Where patching is delayed, reduce attack surface: firewall FTP, DNS management, Strapi admin, and Document Server ports to trusted source ranges; place admin panels behind VPN or an identity-aware proxy; disable unused ProFTPD modules; ensure all five services run under dedicated unprivileged accounts with no sudo rights.
  5. Hunt before you trust. Patching does not evict an intruder. Run the detection content above across at least 30 days of historical telemetry before and after patching. Look specifically for web shells in Document Server and Strapi upload directories, cron/systemd persistence created by service accounts, and egress from DNS/FTP hosts to rare destinations.
  6. Validate externally. Re-scan from outside the perimeter to confirm the vulnerable versions are no longer reachable, and add all five product classes to your continuous attack-surface monitoring.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.