Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Improper Access Control in ProFTPD (CVE‑2015‑3306) Exploited by Flax Typhoon

Flax Typhoon is weaponising CVE‑2015‑3306, a critical improper‑access‑control bug in ProFTPD that grants unauthenticated file‑system access. Organizations must patch and prove control‑area compliance to satisfy audit expectations.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Improper Access Control in ProFTPD (CVE‑2015‑3306) Exploited by Flax Typhoon Threat Actor

What It Is — A critical improper‑access‑control flaw in the open‑source ProFTPD FTP server allows an unauthenticated attacker to bypass authentication and gain full file‑system access.

Exploitability — Actively exploited in the wild by the China‑linked “Flax Typhoon” group; CVSS 3.1 base score 10.0 (critical). No public proof‑of‑concept is required – the vulnerability is weaponised in multiple campaigns.

Affected Products — ProFTPD (all versions prior to the security‑only release that addresses CVE‑2015‑3306).

Why It Matters for Trust & Control Assurance

  • Access‑control hygiene is a core control objective; a single bypass defeats the “least‑privilege” guarantee that auditors expect.
  • Continuous evidence of patch status and configuration drift detection is essential to prove due‑diligence during a security review.
  • Demonstrable logging of FTP authentication attempts provides a defensible audit trail that regulators and enterprise buyers increasingly demand.

Recommended Actions

  • Patch immediately to the version that resolves CVE‑2015‑3306 (or apply the vendor‑provided back‑port).
  • Validate configuration – ensure AllowOverwrite and AuthUserFile directives follow the principle of least privilege.
  • Enable and centralise FTP logs – forward to a SIEM or log‑aggregation service for real‑time monitoring.
  • Run a vulnerability scan focused on known KEV entries to confirm no other catalogued flaws remain unaddressed.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →