What the October 8 KEV additions set as a deadline
CISA's catalog shows October 11, 2026 as the due date on entries added October 8, including CVE-2015-3306. Two reports list four more products on that same clock.
The short version
October 11, 2026. The catalog entry for CVE-2015-3306 carries that due date, and two reports say four more flaws were added the same day with the same date.
What happened
On October 8, 2026, CISA's Known Exploited Vulnerabilities catalog added entries with a due date of October 11, 2026. The catalog entry for CVE-2015-3306, in ProFTPD, is dated that day and describes an improper access control issue that could allow remote reading and writing of files. The Hacker News and Severity Daily report four further additions the same day, with the same due date: CVE-2021-3199 in ONLYOFFICE Docs, CVE-2023-22894 in Strapi, CVE-2016-3081 in Apache Struts, and CVE-2015-5477 in ISC BIND. The page filing the deadline, not a procedure, is Futureweb.
What the catalog requires
The action on the ProFTPD entry is to apply mitigations according to the vendor, or to stop using the product if mitigations are unavailable, and to follow CISA's forensic-triage note. Severity Daily says the same due date and the same style of action sit on all five. The date binds federal civilian agencies. CISA's own catalog language treats everyone else as a reader of a priority list, not as an agency under the order. The desk is Security.
What the impact classes are
In the accounts this page is using, ProFTPD is improper access control with a risk of remote file access. ONLYOFFICE Docs is a path traversal with a risk of remote code execution. Strapi is storage of sensitive information in cleartext, reachable from an admin panel. Apache Struts is command injection with a risk of remote code execution. BIND is a denial of service. Those are classes. This page does not print the commands, parameters, or query types in the writeups. What the KEV catalog adds, as a standing explainer, is what the KEV catalog adds.
Why it matters on this desk
The check is an add date, a due date, five identifiers, and five products. Federal agencies have until Sunday, October 11, 2026. A reader outside that set can still see that CISA says the flaws are known to be exploited. The catalog entry this page read does not name a group. The Hacker News says the additions follow exploitation it associates with Flax Typhoon. Yesterday's brief on the domain seizures is a different document, what the Flax Typhoon seizure release alleges.
What this page will not merge
The seizure announcement and the catalog additions share a news cycle and, in one outlet, a group name. They are not the same document. The seizure is a Justice Department release about two tools. The catalog is a due date on five older flaws. Treating the outlet's group name as a line in the catalog would close a gap the catalog entry left open. What a CVE identifier is, which these five already have, is what a CVE identifier is.
What Severity Daily adds about the clock
Severity Daily says the public catalog file moved to a version dated October 8 and that the count rose by five, each with the October 11 due date. It also says a three-day federal clock is a band in CISA's current directive, not an explanation of why these five landed in that band. This page does not reconstruct that scoring. The readable fact is the date. A networking brief about certificate lifetimes filed the same day is a different subject, on Networking.
What to watch next
October 11, 2026 is the due date. A catalog correction that drops one of the five, or a CISA note that names a threat group in the entry itself, would change the sentences above. A later story that only repeats the outlet's group name would not. The October 8 catalog is the record for the deadline. What an advisory has to name, apart from a catalog due date, is the advisory.
What would change the list
A vendor advisory that says a named version is the fix would let this page add a version. The entries in hand say to apply the vendor's mitigations or discontinue the product. They do not, in the text used here, print those version numbers. Until they do, the identifiers and the due date are the brief. Another outlet's score table does not replace the catalog.
What stays a catalog deadline
What stays specific is five known-exploited entries added October 8, 2026, due October 11, 2026, covering ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and BIND. The federal action is to mitigate or stop using the product. The group name is an outlet's attribution, not a line this page found in the ProFTPD catalog entry. It is not a how-to. It is not the domain-seizure case. The catalog and the two reports agree on the date. They do not all agree on who exploited the flaws, and this page does not pretend they do. The catalog is the authority for the due date. The Hacker News is the authority for its own group attribution, which this brief labels as such. Severity Daily is the check that the public catalog file's count rose by five on October 8. A reader who needs a patch command has the vendor, not this page. A reader who needs to know whether Sunday is the federal date can stop at October 11, 2026. That is the whole operational fact the catalog is willing to state in the entry this page read. The rest is classification: product, identifier, and impact class, without a reproduction. Yesterday's seizure brief stays yesterday's. This one is a clock.
Sources
The reports this brief is filing. Futureweb did not republish them.
Questions
What due date does CISA's catalog show for the October 8, 2026 additions?
October 11, 2026. The catalog entry for CVE-2015-3306, added that day, carries that due date. The Hacker News and Severity Daily report the same date on five additions.
Which products do the October 8 KEV reports name?
ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND, under CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-2016-3081, and CVE-2015-5477.
Who does the October 11 KEV date bind?
Federal civilian agencies, under CISA's catalog action: apply the vendor's mitigations, or stop using the product if mitigations are unavailable. The catalog encourages others to use the list. It does not by itself bind them.
Does CISA's catalog entry name Flax Typhoon?
The catalog text this page is using for CVE-2015-3306 does not. The Hacker News attributes the five additions to exploitation it associates with Flax Typhoon. That attribution stays with the outlet.
Does this page explain how any of the five flaws is used?
No. It files the identifiers, the products, the impact class, the add date, and the due date. It does not include commands or a reproduction.