CISA Adds Five Actively Exploited Vulnerabilities in Apache Struts, BIND, ProFTPD, Strapi and ONLYOFFICE Docs to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on October 8, 2026, confirming that they are being actively exploited in real-world attacks.
The newly listed flaws affect Apache Struts, BIND, ProFTPD, Strapi, and ONLYOFFICE Docs. All five vulnerabilities received CVE identifiers between 2015 and 2023. CISA directed U.S. federal agencies to complete remediation by October 11, 2026, and urged organizations to investigate potential compromises.
Particular attention was given to the headless CMS Strapi vulnerability CVE-2023-22894. The issue arises because sensitive information is stored in plaintext. An attacker who gains access to the administrative interface can use query filters to retrieve highly sensitive user data.
When CVE-2023-22894 is chained with CVE-2023-22621, the combination allows remote code execution. CISA noted that some affected product versions may have reached end-of-life status, increasing the risk for organizations still running unsupported deployments.
The agency continues to maintain the KEV catalog as a prioritized list of vulnerabilities that threat actors are actively exploiting, helping defenders focus remediation efforts on the most urgent threats.
Related articles
FBI Issues Alert on Active FortiBleed Campaign Harvesting Credentials from Exposed FortiGate Firewalls
The FBI and United States Secret Service have issued a joint alert regarding the FortiBleed campaign, an ongoing operation that targets internet-exposed FortiGate firewalls and SSL VPN gateways. Attackers have already collected 86,644 valid credentials from devices across 194 countries as of June 19, demonstrating the global scale of the indiscriminate scanning effort. The campaign relies on reused or previously leaked credentials combined with legacy SHA-256 password storage that enables offline cracking. Operators employ automated credential stuffing, the Go-based FortigateSniffer tool capable of intercepting 24 authentication protocols, and GPU-accelerated password cracking. Once inside, attackers create unauthorized administrator accounts and often delete legitimate ones, forcing victims to perform full device recovery rather than simple password resets. The activity was first documented in June, with the official alert released on October 7, confirming that scanning continues.
Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical
Cisco Systems has released security updates addressing 14 vulnerabilities in its Cisco NX-OS Software used in network devices. Four of the seven security advisories published on October 7, 2026, are rated Critical, while three are rated Medium. Several critical issues affect the Cisco Nexus 3000 Series and Nexus 9000 Series switches, impacting features such as NGOAM, MPLS OAM, and the NX-API management interface. Seven vulnerabilities received CVSSv3.1 base scores of 9.0 or higher, with multiple flaws enabling remote code execution as root or denial-of-service conditions. Specific CVEs including CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 stem from input validation failures in the NGOAM feature and may require SRv6 or NV Overlay configurations to be exploitable. The advisories also cover control plane denial-of-service issues, Python sandbox escapes, and endpoint group contract bypasses in ACI mode.
HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical
Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.
Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release
Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.