type: cve · created: 2026-10-09 · updated: 2026-10-09 · tags: [cve] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false
The advisory lists eight exploited CVEs — including CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE) and CVE-2023-22894 (Strapi) — that also appear in CISA's KEV additions of the same day.
| Attribute | Detail |
|---|---|
| CVE | CVE-2021-3199 |
| CVSS | 9.8 (CRITICAL) |
| Vendor / product | ONLYOFFICE Docs |
| Reported | 2026-10-09 |