CISA Adds Five Vulnerabilities to KEV Catalog Following Flax Typhoon Exploitation
Federal agencies directed to patch by October 11; includes ProFTPD and Windows privilege escalation flaws

Key Takeaways
- CISA added five vulnerabilities to its KEV catalog due to active exploitation by Flax Typhoon.
- The flaws include one ProFTPD vulnerability and four Windows component flaws.
- Federal agencies must patch by October 11, 2026.
- Flax Typhoon is a China-linked threat actor actively exploiting these flaws in the wild.
Related Security News

Hackers Earn $1,262,000 for 98 Zero-Days at Pwn2Own Ireland 2026
At the Pwn2Own Ireland 2026 hacking contest, participants collected $1,262,000 in rewards after successfully exploiting 98 zero-day vulnerabilities across various platforms. The event, which concluded on October 9, 2026, saw researchers chain multiple exploits to compromise target systems, with prize money distributed according to exploit complexity and chain length. Organizers and participants are coordinating findings with affected vendors for CVE assignment and remediation.




