CISA's Known Exploited Vulnerabilities catalog just absorbed six new entries in a four-day window (October 4–8, 2026), and the composition of this batch should concern every defender running internet-facing infrastructure. This is not a drill-down on theoretical risk — every CVE below has confirmed in-the-wild exploitation. Under Binding Operational Directive 22-01, federal civilian agencies face mandatory remediation deadlines, and the same exploitation pressure is hitting enterprise networks globally.
The batch is notable for two reasons: the inclusion of a brand-new 2026 Citrix NetScaler flaw (CVE-2026-88779) — historically the fastest-weaponized product class in the KEV — and the resurrection of decade-old vulnerabilities in BIND, ProFTPD, and Apache Struts that threat actors are still finding profitable against unpatched legacy estates.
Active Exploitation Intelligence
CVE-2026-88779 — Citrix NetScaler ADC / Gateway | Added 2026-10-04
- Vulnerability class: Improper restriction of operations within the bounds of a memory buffer (CWE-119) in NetScaler ADC and NetScaler Gateway.
- Exploitation method: Remote, unauthenticated memory corruption against the gateway appliance — the same attack surface class as CitrixBleed (CVE-2023-4966) and CVE-2023-3519, both of which were weaponized within days.
- Threat actor profile: NetScaler flaws of this class are historically exploited by initial access brokers (IABs) and ransomware affiliates (LockBit, Medusa, and Akira ecosystems have all leveraged NetScaler edge bugs) as well as nation-state actors for stealthy persistence on edge devices.
- CVSS: Pending full NVD enrichment; treat as CRITICAL (9.x-equivalent risk posture) given the product class and exploitation confirmation.
- PoC status: No public PoC confirmed at time of writing, but KEV listing indicates working private exploit code is circulating.
- CISA required action: Apply vendor mitigations/patches per Citrix advisory. Federal deadline: October 25, 2026.
- Priority: PATCH FIRST. Edge appliance + unauthenticated + active exploitation = maximum urgency.
CVE-2016-3081 — Apache Struts 2 | Added 2026-10-08
- Vulnerability class: Command injection / OGNL injection via Dynamic Method Invocation (DMI).
- Exploitation method: Remote code execution. When DMI is enabled, attackers pass a crafted
method:prefix parameter (e.g.,method:<ognl-payload>) to execute arbitrary OGNL expressions, achieving full RCE in the context of the Struts application. - Affected versions: Struts 2.3.20 through 2.3.28 (excluding 2.3.20.3 and 2.3.24.3) with DMI enabled (
struts.enable.DynamicMethodInvocation = true). - CVSS: 9.8 (Critical).
- PoC status: Public PoC has existed since 2016; Metasploit module available. Trivial to weaponize.
- Threat actor profile: Struts RCEs have been a perennial favorite of cryptominers, botnets (Mirai variants), Chinese APT clusters, and ransomware IABs since the Equifax breach (CVE-2017-5638). Re-listing signals renewed scanning/exploitation of legacy Java estates.
- CISA required action: Apply mitigations per vendor guidance or discontinue the product if EOL. Federal deadline: October 29, 2026.
CVE-2015-3306 — ProFTPD | Added 2026-10-08
- Vulnerability class: Improper access control in
mod_copy(CWE-284). - Exploitation method: Unauthenticated remote attackers use the
SITE CPFR/SITE CPTOFTP commands to read and write arbitrary files on the server — commonly abused to write PHP webshells into webroot directories for full RCE. - Affected versions: ProFTPD 1.3.5 and earlier with
mod_copyenabled (default in many distributions). - CVSS: 10.0 (Critical) under v2 scoring; effectively a pre-auth arbitrary file write.
- PoC status: Public exploit code available since 2015; Metasploit module exists.
- Threat actor profile: Long history of exploitation by webshell operators and hosting-environment mass-compromise crews; resurgence typically correlates with botnet expansion campaigns.
- CISA required action: Apply mitigations per vendor guidance. Federal deadline: October 29, 2026.
CVE-2015-5477 — ISC BIND | Added 2026-10-08
- Vulnerability class: Data processing error (improper TKEY query handling) in
named. - Exploitation method: Remote denial of service. A single crafted TKEY packet causes an assertion failure and crashes the
namedprocess — one packet takes down authoritative and recursive DNS. - Affected versions: BIND 9.1.0 through 9.9.7-P1 and 9.10.0 through 9.10.2-P2.
- CVSS: 7.8 (High) — note the impact is availability-only, but DNS is a blast-radius multiplier.
- PoC status: Public PoC/exploit available since 2015.
- Threat actor profile: Historically abused for DNS disruption; in the modern context, used to blind or degrade SOC telemetry pipelines and as a diversion during ransomware intrusions.
- CISA required action: Apply vendor mitigations. Federal deadline: October 29, 2026.
CVE-2021-3199 — ONLYOFFICE Docs | Added 2026-10-08
- Vulnerability class: Path traversal (CWE-22) in image upload handling when JWT authentication is in use.
- Exploitation method: Attackers inject a
/..sequence into an image upload parameter to traverse outside the intended directory, enabling arbitrary file read/write on the document server — a path to webshell deployment and RCE. - Affected versions: ONLYOFFICE Docs (DocumentServer) prior to 6.1.
- CVSS: High (7.5–8.6 range under NVD assessment).
- PoC status: Technical details publicly documented; exploitation is straightforward for exposed DocumentServer instances.
- Threat actor profile: Collaboration/document platforms are attractive to espionage actors and ransomware crews seeking internal document access and lateral-movement footholds.
- CISA required action: Apply vendor patch (upgrade to fixed DocumentServer release). Federal deadline: October 29, 2026.
CVE-2023-22894 — Strapi | Added 2026-10-08
- Vulnerability class: Cleartext storage of sensitive information (CWE-312) in the Strapi CMS admin panel.
- Exploitation method: Attackers with access to the admin panel (via credential theft, brute force, or chaining with an auth bypass such as the related CVE-2023-22893 SSO flaw) can disclose stored sensitive information, enabling account takeover and downstream compromise.
- Affected versions: Strapi versions prior to the 4.6.x fix line.
- CVSS: Medium-to-High standalone; severity escalates sharply when chained.
- PoC status: Public technical write-ups exist; exploitation typically occurs as part of a chain rather than standalone.
- Threat actor profile: CMS compromise chains are staples of IABs harvesting credentials and data for ransomware staging.
- CISA required action: Apply vendor patch. Federal deadline: October 29, 2026.
Affected Organizations Assessment
Exposed environments
- Citrix NetScaler ADC/Gateway: Tens of thousands of internet-facing appliances globally, concentrated in enterprise remote access, healthcare, finance, legal, and government. NetScaler is the single most abused edge product in KEV history — assume scanning began within hours of listing.
- Apache Struts 2: Legacy Java application servers in banking, insurance, government portals, and e-commerce. DMI-enabled Struts 2.3.x apps persist in long-tail enterprise applications that were never rebuilt. Shodan and census data consistently show thousands of identifiable Struts deployments.
- ProFTPD: Shared hosting providers, ISP infrastructure, and Linux FTP services.
mod_copyships enabled by default in many distro packages, massively widening the blast radius. - ISC BIND: The backbone of internet DNS. Any organization still running BIND 9.9/9.10-era resolvers or authoritative servers is one packet away from a DNS outage.
- ONLYOFFICE Docs: Self-hosted collaboration deployments, frequently integrated with Nextcloud/ownCloud — popular in legal, education, and EU public sector.
- Strapi: Headless CMS deployments behind APIs and marketing sites; often internet-reachable admin panels with weak authentication hygiene.
Exposure scale and patch adoption
Legacy CVEs (2015–2016) appearing in KEV a decade later is a direct indictment of patch adoption: CISA only lists vulnerabilities with current confirmed exploitation, meaning unpatched 2015-era ProFTPD and BIND instances remain common enough to be profitable targets. Industry patch telemetry consistently shows 10–20% of exposed legacy services remain unpatched for years after disclosure. Expect the oldest flaws here to have the largest raw exposure count, while CVE-2026-88779 has the highest exploitation velocity.
Fastest-exploited sectors by product type
- Edge appliances (NetScaler): Financial services, healthcare, government — historically weaponized in under 72 hours.
- Web frameworks (Struts, Strapi): Retail, banking, higher education.
- Infrastructure services (BIND, ProFTPD): ISPs, hosting providers, telecom — disruption and mass-compromise value.
- Collaboration platforms (ONLYOFFICE): Legal, public sector, education.
Detection Engineering
The following Sigma rules target observable exploitation behaviors for the highest-risk CVEs in this batch: Struts DMI OGNL injection, ProFTPD mod_copy abuse, NetScaler anomalous requests, and ONLYOFFICE path traversal.
---
title: Apache Struts 2 DMI OGNL Injection Attempt (CVE-2016-3081)
id: 9f2a1c3e-7b4d-4e1a-9c2f-3d8e5a6b7c01
status: experimental
description: Detects Dynamic Method Invocation abuse via method: prefix parameters used for OGNL injection and RCE against Apache Struts 2
author: Security Arsenal Threat Intelligence
date: 2026/10/08
references:
- https://nvd.nist.gov/vuln/detail/CVE-2016-3081
logsource:
category: webserver
product: apache
detection:
selection_uri:
cs-uri-query|contains:
- 'method:'
- 'method%3A'
- '%23_memberAccess'
- 'ognl'
- 'Runtime.getRuntime'
filter_static:
cs-uri-stem|endswith:
- '.css'
- '.png'
- '.ico'
condition: selection_uri and not filter_static
falsepositives:
- Legitimate Struts applications using DMI (should be disabled in production)
level: high
tags:
- attack.initial_access
- attack.t1190
- cve.2016.3081
---
title: ProFTPD mod_copy SITE CPFR CPTO Abuse (CVE-2015-3306)
id: 1a3b5c7d-2e4f-4a6b-8c9d-0e1f2a3b4c02
status: experimental
description: Detects unauthenticated arbitrary file copy/read via ProFTPD mod_copy SITE CPFR and SITE CPTO commands, commonly used to plant webshells
author: Security Arsenal Threat Intelligence
date: 2026/10/08
references:
- https://nvd.nist.gov/vuln/detail/CVE-2015-3306
logsource:
service: ftp
detection:
selection:
ftp_command|contains:
- 'SITE CPFR'
- 'SITE CPTO'
- 'site cpfr'
- 'site cpto'
condition: selection
falsepositives:
- Rare legitimate administrative file operations
level: critical
tags:
- attack.initial_access
- attack.t1190
- attack.t1505.003
- cve.2015.3306
---
title: Edge Appliance Anomalous Request - NetScaler and Path Traversal (CVE-2026-88779 / CVE-2021-3199)
id: 5e6f7a8b-9c0d-4e1f-2a3b-4c5d6e7f8a03
status: experimental
description: Detects suspicious request patterns against NetScaler Gateway endpoints and path traversal sequences in document server upload parameters
author: Security Arsenal Threat Intelligence
date: 2026/10/08
references:
- https://nvd.nist.gov/vuln/detail/CVE-2021-3199
logsource:
category: webserver
detection:
selection_netscaler:
cs-uri-stem|contains:
- '/vpn/'
- '/logon/'
- '/cgi/'
cs-method:
- 'POST'
- 'PUT'
selection_traversal:
cs-uri-query|contains:
- '/..'
- '%2f..'
- '..%2f'
- '%2e%2e'
selection_upload:
cs-uri-stem|contains:
- 'upload'
- 'image'
condition: selection_netscaler or (selection_traversal and selection_upload)
falsepositives:
- Legitimate VPN logon traffic (tune NetScaler selection to your gateway hostnames)
level: high
tags:
- attack.initial_access
- attack.t1190
- attack.t1006
Hunt query for Microsoft Sentinel covering Struts DMI injection, ProFTPD SITE CPFR, ONLYOFFICE traversal, and anomalous NetScaler POSTs across IIS, WAF, and CommonSecurityLog data:
let timeframe = 7d;
let strutsPatterns = dynamic(["method:", "method%3A", "%23_memberAccess", "Runtime.getRuntime"]);
let traversalPatterns = dynamic(["/..", "%2f..", "..%2f", "%2e%2e%2f"]);
let cpfrPatterns = dynamic(["SITE CPFR", "SITE CPTO", "site cpfr", "site cpto"]);
union isfuzzy=true
(W3CIISLog
| where TimeGenerated > ago(timeframe)
| extend Indicators = strcat(csUriStem, " ", csUriQuery)
| where Indicators has_any (strutsPatterns) or csUriQuery has_any (traversalPatterns)
| extend AlertType = case(
Indicators has_any (strutsPatterns), "CVE-2016-3081 Struts DMI Injection",
"CVE-2021-3199 Path Traversal")
| project TimeGenerated, AlertType, cIP, sIP, sPort, csUriStem, csUriQuery, csUserAgent, scStatus),
(CommonSecurityLog
| where TimeGenerated > ago(timeframe)
| where RequestURL has_any (strutsPatterns) or RequestURL has_any (traversalPatterns) or Message has_any (cpfrPatterns)
| extend AlertType = case(
RequestURL has_any (strutsPatterns), "CVE-2016-3081 Struts DMI Injection",
Message has_any (cpfrPatterns), "CVE-2015-3306 ProFTPD mod_copy Abuse",
"CVE-2021-3199 Path Traversal")
| project TimeGenerated, AlertType, SourceIP, DestinationIP, DestinationPort, RequestURL, Message, DeviceVendor, DeviceProduct),
(Syslog
| where TimeGenerated > ago(timeframe)
| where SyslogMessage has_any (cpfrPatterns)
| extend AlertType = "CVE-2015-3306 ProFTPD mod_copy Abuse"
| project TimeGenerated, AlertType, HostIP, Computer, SyslogMessage)
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), HitCount = count()
by AlertType, cIP, sIP, csUriStem, csUserAgent
| order by HitCount desc
Inventory and remediation validation script — identifies exposed BIND, ProFTPD, and Struts instances, checks ONLYOFFICE/Strapi versions where detectable, and flags NetScaler builds requiring vendor validation:
# Security Arsenal - KEV Wave 2026-10-04/08 Exposure Inventory
# Run as Administrator. Outputs JSON report per host.
$report = [ordered]@{
Hostname = $env:COMPUTERNAME
ScanTime = (Get-Date).ToString('o')
Findings = @()
}
function Add-Finding($cve, $product, $status, $detail) {
$script:report.Findings += [pscustomobject]@{
CVE = $cve; Product = $product; Status = $status; Detail = $detail
}
}
# --- CVE-2015-5477: ISC BIND version check ---
$named = Get-Command named -ErrorAction SilentlyContinue
if ($named) {
$bindVer = (& named -v 2>$null) -replace 'BIND ',''
$v = [version]($bindVer -split '-' | Select-Object -First 1)
if ($v -lt [version]'9.9.7.2' -or ($v.Major -eq 9 -and $v.Minor -eq 10 -and $v -lt [version]'9.10.2.3')) {
Add-Finding 'CVE-2015-5477' 'ISC BIND' 'VULNERABLE' "Version $bindVer exposed to TKEY DoS - upgrade to 9.9.7-P2 / 9.10.2-P3 or later"
} else {
Add-Finding 'CVE-2015-5477' 'ISC BIND' 'PATCHED' "Version $bindVer"
}
}
# --- CVE-2015-3306: ProFTPD + mod_copy check ---
$proftpd = Get-Command proftpd -ErrorAction SilentlyContinue
if ($proftpd) {
$pVer = (& proftpd -v 2>$null)
$modules = (& proftpd -l 2>$null)
if ($pVer -match '1\.3\.5|1\.3\.[0-4]' -and $modules -match 'mod_copy') {
Add-Finding 'CVE-2015-3306' 'ProFTPD' 'VULNERABLE' "$pVer with mod_copy enabled - disable mod_copy or upgrade"
} else {
Add-Finding 'CVE-2015-3306' 'ProFTPD' 'REVIEW' "$pVer - verify mod_copy status"
}
}
# --- CVE-2016-3081: Struts 2 DMI jars on disk ---
$strutsJars = Get-ChildItem -Path 'C:\','/opt','/var/lib' -Recurse -Filter 'struts2-core-2.3.*.jar' -ErrorAction SilentlyContinue
foreach ($jar in $strutsJars) {
if ($jar.Name -match '2\.3\.(2[0-8]|\d)(?!\.\d)' -and $jar.Name -notmatch '2\.3\.(20\.3|24\.3)') {
Add-Finding 'CVE-2016-3081' 'Apache Struts' 'VULNERABLE' "$($jar.FullName) - verify DMI disabled and upgrade to 2.3.28.1+"
}
}
# Check for DMI enabled in struts config
$strutsCfg = Get-ChildItem -Path 'C:\','/opt','/var/lib' -Recurse -Filter 'struts.xml' -ErrorAction SilentlyContinue
foreach ($cfg in $strutsCfg) {
if ((Get-Content $cfg.FullName -Raw -ErrorAction SilentlyContinue) -match 'DynamicMethodInvocation"\s*value="true') {
Add-Finding 'CVE-2016-3081' 'Apache Struts' 'VULNERABLE' "DMI ENABLED in $($cfg.FullName)"
}
}
# --- CVE-2021-3199: ONLYOFFICE DocumentServer check ---
$ooPaths = @('C:\Program Files\ONLYOFFICE','/var/www/onlyoffice')
foreach ($p in $ooPaths) {
if (Test-Path $p) {
Add-Finding 'CVE-2021-3199' 'ONLYOFFICE Docs' 'REVIEW' "Installation found at $p - confirm DocumentServer >= 6.1"
}
}
# --- CVE-2026-88779: NetScaler requires appliance-side check ---
# SSH to appliance and run: show ns version
# Affected builds: validate against Citrix advisory for CVE-2026-88779 immediately.
$report | ConvertTo-Json -Depth 4 | Out-File "$env:COMPUTERNAME-kev-inventory.json"
$report.Findings | Format-Table -AutoSize
Patch & Remediation Priorities
Patch order (by exploitation velocity and impact)
- CVE-2026-88779 — Citrix NetScaler ADC/Gateway — Unauthenticated edge exploitation confirmed. Apply the Citrix security update immediately; check for IOCs and unauthorized sessions before and after patching (patch alone does not evict implanted actors). Advisory: https://support.citrix.com — search CVE-2026-88779. Federal deadline: 2026-10-25.
- CVE-2016-3081 — Apache Struts — Public PoC + Metasploit + pre-auth RCE. Upgrade to Struts 2.3.28.1 or later and disable DMI (
struts.enable.DynamicMethodInvocation=falsein struts.xml). Advisory: https://cwiki.apache.org/confluence/display/WW/S2-033. Deadline: 2026-10-29. - CVE-2015-3306 — ProFTPD — Pre-auth arbitrary file write → webshell → RCE. Upgrade to ProFTPD 1.3.5a/1.3.6rc1+ or disable
mod_copy. Advisory: http://bugs.proftpd.org/show_bug.cgi?id=4169. Deadline: 2026-10-29. - CVE-2021-3199 — ONLYOFFICE Docs — Upgrade DocumentServer to 6.1 or later; enforce strong JWT secrets. Advisory: https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md. Deadline: 2026-10-29.
- CVE-2015-5477 — ISC BIND — Upgrade to BIND 9.9.7-P2 / 9.10.2-P3 or a current supported release (9.16/9.18 ESV). Advisory: https://kb.isc.org/docs/cve-2015-5477. Deadline: 2026-10-29.
- CVE-2023-22894 — Strapi — Upgrade to the fixed 4.6.x+ release line; rotate any credentials or secrets stored in the admin panel; audit admin access. Advisory: https://github.com/strapi/strapi/security/advisories. Deadline: 2026-10-29.
Workarounds where patching is not immediately possible
- NetScaler: No reliable workaround for memory-corruption class flaws — patching is the only mitigation. If you cannot patch, take the appliance offline or place it behind a strictly allow-listed VPN/WAF, and hunt for compromise.
- Struts: Disable Dynamic Method Invocation globally; deploy WAF rules blocking
method:parameters and OGNL metacharacters. - ProFTPD: Remove or comment
mod_copyfrom the module load list and restart the service. - BIND: Filter malformed TKEY queries at the network edge where feasible (fragile); restrict recursive access to trusted clients.
- ONLYOFFICE: Block external access to DocumentServer upload endpoints; enforce JWT validation at the reverse proxy.
- Strapi: Restrict admin panel to VPN/allow-listed IPs; enable MFA; audit stored credentials.
Analyst Bottom Line
The presence of CVE-2026-88779 means you have a 72-hour problem on any internet-facing NetScaler. The presence of three 2015–2016 CVEs means your attackers are harvesting the unpatched long tail — and if CISA is confirming exploitation now, someone in your sector is already a victim. Run the inventory script today, prioritize the edge, and treat every October 29 deadline as already late.
Related Resources
Security Arsenal Penetration Testing Managed SOC & MDR AlertMonitor Platform From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.