Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

ProFTPD Improper Access Control: CISA Sets 11 October KEV Deadline

Federal agencies must mitigate the ProFTPD file copy flaw by 11 October after CISA added it to the Known Exploited Vulnerabilities catalog.

ProFTPD Improper Access Control: CISA Sets 11 October KEV Deadline
Illustration: Firewall Pulse

Key points

  • CISA added CVE-2015-3306 to the KEV catalog on 8 October 2026 with a federal due date of 11 October 2026.
  • The vulnerability allows remote attackers to read and write arbitrary files using the site cpfr and site cpto commands.
  • The flaw is linked to abuse by the China-linked threat actor Flax Typhoon, according to The Hacker News.

CISA has added an improper access control vulnerability in ProFTPD to its Known Exploited Vulnerabilities (KEV) catalog, imposing a strict mitigation deadline for federal agencies. The entry, published on 8 October 2026, requires compliance by 11 October 2026. This action follows reports that the China-linked threat actor Flax Typhoon has exploited this flaw, as noted by The Hacker News.

Root cause

The issue stems from the mod_copy module within ProFTPD. Specifically, the module fails to enforce proper access controls when handling specific FTP commands. This design flaw permits unauthorised file operations that bypass standard permission checks.

Attack path

Remote attackers can leverage this vulnerability to read and write to arbitrary files on the target system. The attack vector utilises the site cpfr and site cpto commands. By sending these commands, an attacker can copy files from or to any location on the filesystem, effectively granting full read and write access to the server.

Affected versions

  • ProFTPD 1.3.5 is explicitly identified in the NVD record as affected.
  • The vulnerability is associated with the mod_copy module.
  • Earlier or later versions may also be susceptible if they include the vulnerable module configuration, though specific version ranges beyond 1.3.5 are not detailed in the source material.

Mitigation

  • Apply mitigations in accordance with vendor instructions.
  • Ensure compliance with CISA’s BOD 26-04 Prioritising Security Updates Based on Risk guidance.
  • Follow CISA’s Forensics Triage Requirements.
  • Discontinue use of the product if mitigations are unavailable, particularly for cloud services.
  • Evaluate each asset's internet exposure to ensure adherence to patching guidelines.

What to do and how to stay safe: ProFTPD

  • Audit all FTP servers to identify if ProFTPD 1.3.5 or versions containing the mod_copy module are in use.
  • Restrict network access to FTP services to trusted IP ranges only, reducing the attack surface for remote exploitation.
  • Monitor logs for unusual usage of the site cpfr and site cpto commands, which may indicate active exploitation.
  • Prepare to disable the mod_copy module or remove ProFTPD if a vendor update is not immediately available, once the vendor provides an update.

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the deadline for federal agencies to mitigate CVE-2015-3306?

The federal due date is 11 October 2026, as set by CISA upon adding the vulnerability to the KEV catalog.

Which threat actor has exploited this vulnerability?

According to The Hacker News, the China-linked threat actor known as Flax Typhoon has abused this flaw.

What commands are used to exploit this vulnerability?

Attackers use the site cpfr and site cpto commands to read and write arbitrary files.

Sources

  1. CISA KEV catalog
  2. The Hacker News
ProFTPDCVE-2015-3306CISAFlax TyphoonFTP

Related stories