Skip to content
eastbaycyber

CISA Adds 5 Known Exploited Vulnerabilities to Catalog (October 8, 2026)

Source: CISA KEV Catalog · Updated 2026-10-08

Summary

On October 8, 2026, CISA added 5 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-5477, CVE-2016-3081, CVE-2023-22894, CVE-2021-3199, CVE-2015-3306. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

ISC · BIND

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

Federal due date
2026-10-11
Ransomware use
Unknown
Added
2026-10-08

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache · Struts

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Federal due date
2026-10-11
Ransomware use
Unknown
Added
2026-10-08

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Apache KEV history

CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi · Strapi

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

Federal due date
2026-10-11
Ransomware use
Unknown
Added
2026-10-08

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE · Docs

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

Federal due date
2026-10-11
Ransomware use
Unknown
Added
2026-10-08

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD · ProFTPD

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Federal due date
2026-10-11
Ransomware use
Unknown
Added
2026-10-08

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

Also added to KEV in October 2026

  • October 4, 2026: CVE-2026-88779, Citrix NetScaler (Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memor)
  • October 2, 2026: CVE-2026-102490, Zammad GmbH Zammad (Zammad GmbH Zammad Improper Privilege Management Vulnerability)
  • October 2, 2026: CVE-2026-102489, Zammad GmbH Zammad (Zammad GmbH Zammad Session Fixation Vulnerability)
  • October 1, 2026: CVE-2026-104286, Fortinet FortiMail (Fortinet FortiMail Path Traversal Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.