Skip to content
TrustList
News

CISA lists old Strapi, ONLYOFFICE and Struts flaws as exploited

Editorial

By TrustList Editorial

All five flaws were fixed between 2015 and 2023, and the newest is a Strapi admin-panel leak fixed in 4.8.0. Federal agencies have until 11 October to deal with them.

About CISA lists old Strapi, ONLYOFFICE and Struts flaws as exploited

CISA lists old Strapi, ONLYOFFICE and Struts flaws as exploited

8 October 2026: The US Cybersecurity and Infrastructure Security Agency has added five vulnerabilities to its Known Exploited Vulnerabilities catalog, all of them patched years ago: a Strapi admin-panel data leak, a path traversal in ONLYOFFICE Docs, command injection in Apache Struts, a denial-of-service bug in ISC BIND and a file read and write flaw in ProFTPD. Federal civilian agencies must deal with all five by 11 October under directive BOD 26-04, a three-day window, and CISA says to stop using a product where no mitigation is available.

Not yet independently verified. CISA does not say who is exploiting these flaws or against which targets, and none of the five vendors has published a new statement. The fixed versions below come from each vendor's original advisory or the NVD record. We will update this when it can be confirmed, and remove this note.

The listing means CISA has evidence of exploitation now, not when the bugs were found. Old flaws keep working where software was installed once and never upgraded, which is common for self-hosted content systems, document servers and FTP boxes.

The five, with the version that fixed each:

  • Strapi, CVE-2023-22894 (CVSS 4.9): an attacker with admin-panel access can filter users on private fields and infer password hashes and reset tokens. Fixed in Strapi 4.8.0. CISA notes it can be chained with CVE-2023-22621, a template injection fixed in 4.5.6, to run code.
  • ONLYOFFICE Docs, CVE-2021-3199 (CVSS 9.8): path traversal in image upload when JWT is used, leading to code execution. Fixed in Document Server 5.6.3.
  • Apache Struts, CVE-2016-3081 (CVSS 8.1): code execution through the method: prefix when Dynamic Method Invocation is on. Affects 2.3.19 to 2.3.28 in three ranges; Apache's bulletin S2-032 gives the fixes.
  • ISC BIND, CVE-2015-5477: a crafted TKEY query stops named. Fixed in 9.9.7-P2 and 9.10.2-P3.
  • ProFTPD, CVE-2015-3306 (CVSS 10 under the older scoring): the mod_copy module lets an unauthenticated user copy files anywhere the server can write. It affects 1.3.5.

Strapi's own advisory is direct about the line: anything from 3.2.1 up to but not including 4.8.0 is affected, and Strapi v3 receives no security updates at all. CISA flags the Strapi entry as possibly end of life, so a v3 install has no patch to apply and needs a migration.

Our headless CMS category lists seven platforms, Strapi among them, and ONLYOFFICE is in our productivity software listings. CISA marks three of the five, Struts, ONLYOFFICE and ProFTPD, for the forensic triage requirements it published alongside BOD 26-04.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy