Five old flaws joined CISA's exploited list on 8 October. One sits in Strapi.
By Lior AharonovFounder, 7IT Solutions ·
On Thursday 8 October 2026, CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog, with a federal deadline of Sunday 11 October. They hit Strapi (CVE-2023-22894), ONLYOFFICE Docs (CVE-2021-3199), Apache Struts (CVE-2016-3081), ISC BIND (CVE-2015-5477) and ProFTPD (CVE-2015-3306).
These are the tickets nobody closed: the Strapi admin behind your marketing site, the document server inside your app. CISA says the Strapi flaw can be chained with CVE-2023-22621 to run code, and the ONLYOFFICE one could allow remote code execution.
Search your servers, container images and old side projects for Strapi, ONLYOFFICE Docs, Struts, BIND and ProFTPD today. Patch what is still supported, and retire any Strapi version past end of life, as CISA advises.
Attackers don't need new bugs while old ones still pay. A 2015 CVE in production isn't legacy. It's an open door.
Lior Aharonov · my takeSources
- CISA Known Exploited Vulnerabilities catalog (official JSON, cisagov/kev-data) raw.githubusercontent.com
- NVD: CVE-2023-22894 (Strapi) nvd.nist.gov
- NVD: CVE-2021-3199 (ONLYOFFICE Docs) nvd.nist.gov
- NVD: CVE-2016-3081 (Apache Struts) nvd.nist.gov
Researched with AI tools; every fact is checked against the linked sources.