{
  "slug": "2026-10-12",
  "date": "2026-10-12",
  "updated": "2026-10-12",
  "title": "Run an FTP server with ProFTPD? Patch it now",
  "intro": "This week's catch-up: four vulnerabilities that vendors fixed years ago have only now been added to the US government's must-patch list, a sign that forgotten, unpatched installs are still being found and attacked. The most urgent: an unauthenticated flaw in ProFTPD, free file-transfer server software, lets an attacker read or write any file on the server. A self-hosted ONLYOFFICE document server, an old custom web application built on Apache Struts, and a website running the Strapi content management system round out the week. If none of those names mean anything to you, nothing here applies to you.",
  "quietWeek": false,
  "items": [
    {
      "id": "proftpd-mod-copy-file-rw",
      "rank": 1,
      "published": "2026-10-08",
      "title": "Run an FTP server with ProFTPD? Patch it now",
      "summary": "ProFTPD is free software some businesses run themselves to accept file uploads or send files back and forth with suppliers and customers over FTP (File Transfer Protocol), instead of paying for a managed file-transfer service. A flaw in one of its add-ons lets anyone connect without logging in at all and tell the server to copy any file to anywhere else on the system, which an attacker can use to read sensitive files or plant one that hands them full control. ProFTPD fixed this back in 2015, but the US government has only now confirmed criminals are actively exploiting it, a sign that old, forgotten installs are still being found on the internet.",
      "whoItAffects": "Businesses that run their own ProFTPD file-transfer server, typically version 1.3.5, set up by an IT provider or an in-house system administrator rather than something that comes pre-installed. If your business exchanges files through a cloud service like Dropbox or SharePoint, or a dedicated SFTP provider, this isn't your equipment.",
      "action": "Ask whoever manages your file-transfer server: \"Are we running ProFTPD, and has it been updated to version 1.3.5a or later?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": ["CVE-2015-3306"],
      "cwes": ["CWE-284"],
      "links": [
        {
          "label": "CISA KEV: ProFTPD flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2015-3306"
        },
        {
          "label": "Debian Security Tracker: CVE-2015-3306",
          "url": "https://security-tracker.debian.org/tracker/CVE-2015-3306"
        }
      ]
    },
    {
      "id": "onlyoffice-docs-path-traversal-rce",
      "rank": 2,
      "published": "2026-10-08",
      "title": "Self-host ONLYOFFICE Docs instead of Microsoft 365? Patch it now",
      "summary": "ONLYOFFICE Docs is software some businesses install on their own server to edit Word, Excel and PowerPoint-style documents, usually chosen instead of Microsoft 365 or Google Workspace for data-control or cost reasons. A flaw in how it handles image uploads lets an attacker slip outside the folder they're meant to use and plant a file that runs their own code on the server, putting every document stored there at risk. ONLYOFFICE fixed the flaw in 2021, but it has only now been confirmed under active attack, suggesting old, un-upgraded installs are still being targeted. If your documents live in Microsoft 365 or Google Workspace, this is not your software.",
      "whoItAffects": "Businesses that specifically chose to self-host ONLYOFFICE Docs (Document Server) rather than use Microsoft 365 or Google Workspace, running a version older than 5.6.3. If the name doesn't ring a bell, you're not running it.",
      "action": "Ask whoever manages your document server: \"Are we running ONLYOFFICE Docs, and has it been updated past version 5.6.3?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": ["CVE-2021-3199"],
      "cwes": ["CWE-22"],
      "links": [
        {
          "label": "CISA KEV: ONLYOFFICE Docs flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2021-3199"
        },
        {
          "label": "HKCERT bulletin: ONLYOFFICE Docs RCE",
          "url": "https://www.hkcert.org/security-bulletin/onlyoffice-docs-remote-code-execution-vulnerability_20261009"
        }
      ]
    },
    {
      "id": "apache-struts-dmi-command-injection",
      "rank": 3,
      "published": "2026-10-08",
      "title": "Run a custom web app built on old Apache Struts? Patch it now",
      "summary": "Apache Struts is a framework developers use to build custom Java-based web applications, things like an internal staff portal or a system built specifically for one business rather than bought off the shelf. In older Struts versions with a feature called Dynamic Method Invocation turned on, an attacker can send a specially crafted request that runs their own code on the server, no login required. Apache fixed this back in 2016, but the US government has only now confirmed criminals are actively exploiting it, a sign that old, never-upgraded custom applications are still out there.",
      "whoItAffects": "Businesses running a custom-built web application on Apache Struts versions 2.3.19 through 2.3.28, usually built by a developer or agency years ago and left running since. If you don't have a custom-built web application, this is a question for whoever would know if you did.",
      "action": "Ask your developer or IT provider: \"Does our application use Apache Struts, is Dynamic Method Invocation turned on, and has it been updated past version 2.3.28.1?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "Web application security"
      },
      "sourceKind": "kev",
      "cves": ["CVE-2016-3081"],
      "cwes": ["CWE-77"],
      "links": [
        {
          "label": "CISA KEV: Apache Struts flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2016-3081"
        },
        {
          "label": "Apache Struts advisory S2-032",
          "url": "https://struts.apache.org/docs/s2-032.html"
        }
      ]
    },
    {
      "id": "strapi-admin-account-takeover",
      "rank": 4,
      "published": "2026-10-08",
      "title": "Run your website on the Strapi CMS? Update it now",
      "summary": "Strapi is free, open-source software, a content management system developers use to build the backend of custom websites and apps instead of something like WordPress. A flaw lets an attacker who isn't logged in trick the admin panel into leaking the code needed to reset a Strapi administrator's password, letting them take over the admin account entirely; chained with a second flaw, that can go all the way to running commands on the server. Strapi fixed it in version 4.8.0, released in 2022, but the US government has only now confirmed it is under active attack, a sign that sites still running old versions are being found and targeted.",
      "whoItAffects": "Businesses whose website or web app was custom-built on Strapi, usually set up by a web developer or agency rather than something you'd recognise yourself. If your website runs on WordPress, Shopify, Squarespace or a similar off-the-shelf platform, this isn't yours.",
      "action": "Ask your web developer or agency: \"Is our site running Strapi, and has it been updated past version 4.8.0?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "Web application security"
      },
      "sourceKind": "kev",
      "cves": ["CVE-2023-22894"],
      "cwes": ["CWE-312"],
      "links": [
        {
          "label": "CISA KEV: Strapi flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894"
        },
        {
          "label": "GitHub Security Advisory GHSA-jjqf-j4w7-92w8",
          "url": "https://github.com/advisories/GHSA-jjqf-j4w7-92w8"
        }
      ]
    }
  ]
}
