CISA Added Five Exploited Vulnerabilities to Catalog

Federal agencies must secure their systems against these specific threats by October 11, 2026.

Updated on Oct. 10, 2026 in Cybersecurity

Bold flat-color editorial illustration of a steel server cabinet, representing critical infrastructure security and federal cybersecurity policy updates.
The Cybersecurity and Infrastructure Security Agency updated its vulnerability catalog to include five flaws actively leveraged by the threat actor Flax Typhoon. AI Illustration. Upload story photo >

Live Poll

Do you trust the federal government to keep critical digital infrastructure secure from foreign cyberattacks?

The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog to include five new security flaws. These vulnerabilities have been actively used by the threat actor Flax Typhoon to target organizations.

Why it matters

These catalog additions aim to prevent unauthorized access and data exfiltration by closing security gaps currently being leveraged in the wild. Ensuring systems are patched is a critical defense against the group's tactics, which include siphoning sensitive emails and credentials.

The newly listed vulnerabilities range from a critical 10.0 CVSS score for CVE-2015-3306 to a 7.2 for CVE-2023-22894. Attackers are using scanning tools, cross-site scripting, and password spraying on Microsoft Exchange servers to maintain persistence.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is the lead federal agency for protecting United States critical infrastructure.

Flax Typhoon

Flax Typhoon is a sophisticated threat actor linked to cyber espionage and the exfiltration of sensitive organizational data.

Integrity Technology Group

Integrity Technology Group is a cybersecurity firm based in China that has been linked to the operations of Flax Typhoon.

The details

The threat actor Flax Typhoon, linked to China-based Integrity Technology Group, utilizes these flaws to establish persistence via VPN software. Attackers deploy custom scripts to exfiltrate email data and network credentials from targeted environments.

Timeline

  1. November 2021: CVE-2019-11510 and CVE-2021-22205 were added to the KEV catalog.

  2. October 2025: CVE-2014-6278 was added to the KEV catalog.

  3. October 8, 2026: CISA officially added five vulnerabilities to the KEV catalog.

  4. October 11, 2026: The deadline for federal agencies to patch or discontinue affected software.

The Tech Race

These updates to the Known Exploited Vulnerabilities catalog reflect the ongoing arms race between federal agencies and sophisticated persistent threats. This effort replaces fragmented security responses with a unified federal mandate to harden infrastructure against emerging exploits.

While the mandate specifically targets federal agencies, private organizations should audit their own systems against these five vulnerabilities to ensure similar protection. Organizations that fail to patch these known flaws remain vulnerable to credential theft and email exfiltration.

The takeaway

Maintaining updated software is the most effective defense against attackers using automated scanning and password spraying tactics. Organizations should prioritize patching these five specific vulnerabilities to neutralize the persistence strategies currently employed by Flax Typhoon.

What happens next

Federal agencies are required to patch the identified software or discontinue its use by October 11, 2026.

Further reading

For more information on national security protocols, visit the Cybersecurity section.

Live Poll

Do you trust the federal government to keep critical digital infrastructure secure from foreign cyberattacks?