BREACH WATCH BRIEF Critical 👤 Vulnerability

Critical Improper Access Control in ProFTPD (CVE‑2015‑3306) Exploited by Flax Typhoon

Flax Typhoon is weaponising CVE‑2015‑3306, a critical improper‑access‑control bug in ProFTPD that grants unauthenticated file‑system access. Organizations must patch and prove control‑area compliance to satisfy audit expectations.

SeverityCritical
Type👤 Vulnerability
ConfidenceHigh
ReportedOct 9, 2026
Other / Unknown organizations running legacy FTP services, especially those in regulated sectors Vulnerability Exploit

What happened

CISA added CVE‑2015‑3306 to its KEV catalog after confirming that the China‑linked Flax Typhoon group is exploiting the flaw to bypass authentication on vulnerable ProFTPD servers. The vulnerability carries a CVSS score of 10.0 and can lead to full system compromise.

Why it matters for trust and compliance

  • The incident underscores the need for robust access‑control governance and continuous evidence of remediation, both of which are essential for audit readiness across multiple frameworks.
  • Continuous monitoring of patch status demonstrates due‑diligence to auditors.
  • Centralised logging of FTP authentication provides defensible evidence of control effectiveness.

Who is affected

organizations running legacy FTP services, especially those in regulated sectors

Recommended actions

  1. Apply the vendor‑released patch for CVE‑2015‑3306 without delay.
  2. Review and harden ProFTPD configuration to enforce least‑privilege access.
  3. Enable detailed FTP logging and ingest logs into a SIEM for real‑time alerting.
  4. Run a KEV‑focused vulnerability scan to verify no other catalogued flaws remain.

Details

CVEs
CVE-2015-3306

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.