CISA AA26-281A: China-linked actors exploit 8 known CVEs

CISA AA26-281A: China-linked actors exploit 8 known CVEs

At a glance

Severity CRITICAL
CVSS CVE-2014-6278: 8.8
EPSS (30-day exploit probability) CVE-2014-6278: 99.6%, CVE-2015-3306: 96.8%, CVE-2015-5477: 91.3%, CVE-2016-3081: 93.4%
In CISA KEV (exploited) Yes, due 2021-11-17, 2022-05-03, 2025-10-23, 2026-10-11
Vendor GNU
CVE IDs CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205

CISA published advisory AA26-281A on October 8, 2026, describing Chinese government-linked threat actors that combine automated scanning, large-scale botnets and hands-on exploitation to steal sensitive data from organizations worldwide, including US critical infrastructure. The advisory lists eight CVEs, and five of them were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog the same day with a due date of October 11, 2026.

This CISA AA26-281A summary focuses on what defenders should check first. According to CISA, the activity is enabled by Integrity Technology Group, a China-based company with links to the Chinese government.

What happened

CISA says the actors use scanning tools, cross-site scripting (XSS) attacks and password spraying against Microsoft Exchange servers. They establish persistence through VPN software and exfiltrate emails and credentials using scripts. The advisory analyses their tactics, techniques and procedures (TTPs) and provides indicators of compromise (IOCs).

CISA names these sectors: government services and facilities, critical manufacturing, healthcare and public health, and information technology. Federal civilian agencies, state, local, tribal and territorial governments and critical infrastructure operators are the stated audience.

Am I affected?

The advisory lists eight CVEs under affected products. The details below come from the CISA KEV catalog and NVD data; versions are only given where NVD lists them.

  • CVE-2014-6278: GNU Bash OS command injection. NVD lists Bash through 4.3 bash43-026 and a CVSS of 8.8 (network vector, user interaction required). Added to KEV on 2025-10-02.
  • CVE-2015-3306: ProFTPD 1.3.5 mod_copy flaw allowing remote file read and write through the site cpfr and site cpto commands.
  • CVE-2015-5477: ISC BIND TKEY query denial of service. NVD lists BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3.
  • CVE-2016-3081: Apache Struts command injection through the method: prefix when Dynamic Method Invocation is enabled.
  • CVE-2019-11510: Ivanti Pulse Connect Secure arbitrary file read. In KEV since 2021-11-03, with known ransomware campaign use.
  • CVE-2021-22205: GitLab Community and Enterprise Editions remote code execution. In KEV since 2021-11-03, with known ransomware campaign use.
  • CVE-2021-3199: ONLYOFFICE Docs path traversal when JWT is used, which could allow remote code execution.
  • CVE-2023-22894: Strapi cleartext storage of sensitive information, exploitable by someone with admin panel access. CISA notes the product may be end-of-life and can be chained with CVE-2023-22621 for remote code execution.

Fixed versions for most of these are not disclosed in the candidate data, so use the vendor advisories.

Technical details

CVE KEV added KEV due EPSS
CVE-2014-6278 2025-10-02 2025-10-23 0.996
CVE-2015-3306 2026-10-08 2026-10-11 0.968
CVE-2015-5477 2026-10-08 2026-10-11 0.913
CVE-2016-3081 2026-10-08 2026-10-11 0.934
CVE-2019-11510 2021-11-03 2022-05-03 1.000
CVE-2021-22205 2021-11-03 2021-11-17 0.997
CVE-2021-3199 2026-10-08 2026-10-11 0.082
CVE-2023-22894 2026-10-08 2026-10-11 0.017

EPSS is the modelled probability of exploitation. Most of these score very high. NVD records CWE-78 for Bash, CWE-284 for ProFTPD and CWE-19 for BIND. For CVE-2015-3306 and CVE-2015-5477 NVD lists no CVSS score. CISA’s KEV entries state that ransomware use is unknown for the five newly added CVEs.

Why this matters

Analysis: most of these flaws are many years old, so the realistic risk is forgotten or unmanaged systems rather than new bugs. Old FTP servers, DNS resolvers, Struts applications and file-sharing or VPN appliances are exactly the assets that tend to sit outside patch cycles. Anything internet-facing that matches the list deserves attention within hours, since five entries carry a three-day KEV deadline.

Indicators and detection

CISA offers downloadable IOCs in STIX XML and STIX JSON formats with the advisory. Individual indicators are not reproduced in the data we reviewed, so pull them from the advisory directly. Hunting ideas that follow from the stated TTPs:

  • Look for password spraying against Exchange, meaning many failed logins across many accounts.
  • Review VPN software for unexpected changes that could indicate persistence.
  • Check for scripts that collect and send out email or credentials.
  • Search web logs for XSS payloads and for unusual ProFTPD site cpfr and site cpto commands.

What to do

  1. Inventory internet-facing Bash-dependent services, ProFTPD, BIND, Struts, Pulse Connect Secure, GitLab, ONLYOFFICE Docs and Strapi.
  2. Apply vendor mitigations or updates. For KEV entries, follow CISA’s required action and the October 11, 2026 due date for the five newly added CVEs. Replace or retire end-of-life products such as Strapi if flagged.
  3. Disable unused services and ports, such as automatic configuration, remote access or file sharing protocols.
  4. Sanitize user input in web applications to prevent XSS payload injection.
  5. Implement identity, credential and access management policies and require multifactor authentication where possible.
  6. Hunt for the behaviors above and import the CISA IOCs into your tooling.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts