CISA AA26-281A: China-Linked Actors Exploit End-of-Life Software
On October 8, 2026 the FBI, CISA, NSA and seven partner agencies from the United Kingdom, Australia, Canada, Japan, New Zealand and Spain released joint cybersecurity advisory AA26-281A, "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data". It describes threat actors enabled by the Integrity Technology Group, a China-based company the advisory links to the Chinese government, whose activity overlaps what the industry tracks as Flax Typhoon, Ethereal Panda and Red Juliett. The advisory's Appendix B lists the eight CVEs the actors successfully exploited. The newest is from 2023; the oldest is from 2014. Read against our lifecycle data, every affected product line we track is past its end-of-life date, and the advisory's own mitigation list says what to do about that in one sentence: "Replace end-of-life products with supported alternatives that are included in vendor support plans."
What the advisory says
AA26-281A is built from evidence recovered in multiple FBI investigations. The threat actors scan with open-source tools (BBScan, dirsearch, Fscan, masscan, NMAP and others), run a Python web application the advisory calls MicroScan that holds over 1,300 penetration-testing scripts, use cross-site scripting payloads to harvest credentials, password-spray Microsoft Exchange servers, keep access through VPN software and exfiltrate email and credentials with scripts. The authoring organizations, in the advisory's own list, are the FBI, CISA, NSA, the United Kingdom's National Cyber Security Centre (NCSC-UK), the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), the Canadian Centre for Cyber Security (Cyber Centre), Japan's National Police Agency (NPA) and National Cybersecurity Office (NCO), New Zealand's National Cyber Security Centre (NCSC-NZ) and Spain's Centro Nacional de Inteligencia (CNI).
The part of the advisory this guide is about is Appendix B, "Observed Common Vulnerabilities and Exposures", a table of eight CVEs with vendor, product, affected versions and vulnerability type, five of them asterisked as "newly added to CISA's Known Exploited Vulnerabilities (KEV) Catalog". Nothing on that list is recent. The MicroScan scripts the actors used targeted OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts; the advisory's reading is that the use of freely available tools "suggests the threat actors tend to look for more vulnerable targets". That is the end-of-life problem stated from the attacker's side: the actors are not spending exploits on current software, they are finding the hosts that never moved.
The Mitigations section lists the usual controls (disable unused services and ports, sanitize web inputs, enforce MFA, segment networks, patch) and, among them, the sentence this site exists to make actionable: "Replace end-of-life products with supported alternatives that are included in vendor support plans." For the eight CVEs below, that sentence is the mitigation that lasts: a later build on the affected line closes the one CVE, but the line itself no longer receives fixes.
The eight CVEs and the lines they live in
Vendor, product and version ranges are as the advisory prints them in Appendix B. End-of-life dates are read from our data and rewritten at every build; KEV dates are read from CISA's catalog. Where we do not track a product, the table says so rather than guessing.
| Product and versions named | CVE | End of life in our data | Added to KEV | KEV due date |
|---|---|---|---|---|
| GNU Bash, through 4.3 bash43-026 | CVE-2014-6278 | Not tracked here (see below) | October 2, 2025 | October 23, 2025 |
| ProFTPD 1.3.5 | CVE-2015-3306 | July 20, 2020 | October 8, 2026 | October 11, 2026 |
| ISC BIND, 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 | CVE-2015-5477 | Not in our data; our BIND coverage begins at 9.16 (March 31, 2024) | October 8, 2026 | October 11, 2026 |
| Apache Struts 2.3, 2.3.19 to 2.3.28 | CVE-2016-3081 | May 14, 2019 | October 8, 2026 | October 11, 2026 |
| Pulse Connect Secure 8.2, 8.3 and 9.0 (now Ivanti Connect Secure) | CVE-2019-11510 | 8.2: July 11, 2018; 8.3: October 11, 2019; 9.0: October 30, 2020 | November 3, 2021 | May 3, 2022 |
| GitLab, all versions starting from 11.9 | CVE-2021-22205 | 13.10, the oldest line in our data: June 22, 2021; every earlier release is older | November 3, 2021 | November 17, 2021 |
| ONLYOFFICE DocumentServer, 5.1.5 through 5.6.2 | CVE-2021-3199 | Not tracked here | October 8, 2026 | October 11, 2026 |
| Strapi 4, up to 4.5.5 | CVE-2023-22894 | June 9, 2026 | October 8, 2026 | October 11, 2026 |
Five of the eight rows share the same two KEV dates because CISA added them together on the day the advisory was released. The other three were in the catalog already: the Pulse Connect Secure and GitLab entries since CISA's first weeks of publishing the catalog, the Bash entry since 2025.
Key dates
- July 11, 2018: Pulse Connect Secure 8.2 reaches end of life, the first of the three Pulse lines the advisory names.
- May 14, 2019: Apache Struts 2.3 reaches end of life.
- October 11, 2019: Pulse Connect Secure 8.3 reaches end of life.
- July 20, 2020: ProFTPD 1.3.5 reaches end of life.
- October 30, 2020: Pulse Connect Secure 9.0 reaches end of life, the newest of the three named lines.
- June 22, 2021: GitLab 13.10, the oldest GitLab line in our data, reaches end of life.
- November 3, 2021: CISA adds CVE-2019-11510 (Pulse Connect Secure) and CVE-2021-22205 (GitLab) to the Known Exploited Vulnerabilities catalog.
- October 2, 2025: CISA adds CVE-2014-6278 (GNU Bash) to the catalog.
- June 9, 2026: Strapi 4 reaches end of life.
- October 8, 2026: AA26-281A is released, and CISA adds the ProFTPD, BIND, Struts, ONLYOFFICE and Strapi CVEs to the catalog the same day.
- October 11, 2026: KEV due date for those five entries, for US federal civilian executive branch agencies.
Five KEV additions with a three-day due date
CISA added the five asterisked entries, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199 and CVE-2023-22894, to the Known Exploited Vulnerabilities catalog on October 8, 2026, the advisory's release date. Each carries a remediation due date of October 11, 2026 for federal civilian executive branch agencies, three days after the entry, the short window CISA uses for entries it regards as most urgent. The usual window is three weeks, which is what the Bash entry got in 2025; the Pulse Connect Secure entry, added in the catalog's first weeks, was given six months.
A three-day due date against a CVE from 2015 is not a comment on how hard the fix is. For each of the five, the vendor fixed the flaw years ago; the entries exist because hosts running the unfixed versions are still being found and exploited. For a federal agency, a later build on the same line (Struts past 2.3.28, ProFTPD 1.3.5 with the vendor's fix) closes this one CVE but leaves the host on a line that stopped receiving fixes years ago, so the durable way to meet the date is to replace the software or take the host off the network. Our guide to CISA's directives covers how the catalog's due dates bind federal agencies and how they are read everywhere else.
Line by line: what is end of life, and what replaces it
Apache Struts 2.3 (CVE-2016-3081, affecting 2.3.19 through 2.3.28). The 2.3 line reached end of life on May 14, 2019; the 2.5 line that followed it reached end of life on April 30, 2024. The supported lines today are Struts 6 and Struts 7, both on our Apache Struts page. In the HeroDevs Never-Ending Support catalog we track, Struts coverage is listed for the 1.x and 2.5 lines; the 2.3 line the advisory names is not listed there as we read it, so the path for a 2.3 host is a move to a supported Struts line.
ProFTPD 1.3.5 (CVE-2015-3306). The 1.3.5 line reached end of life on July 20, 2020. ProFTPD's current line is 1.3.9; 1.3.8 is past active support but not yet end of life in our data, and 1.3.7 ended on March 14, 2025. The advisory notes that the actors scan port 21 specifically. An FTP daemon from 2015 reachable from the internet is the kind of host their scanning is built to find; replace it with 1.3.9 or retire FTP for SFTP.
ISC BIND 9.9 and 9.10 (CVE-2015-5477, 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3). Our BIND data begins at 9.16, which itself reached end of life on March 31, 2024; 9.9 and 9.10 predate it, and we carry no dates for them, so we make no dated claim here beyond the obvious one that they are older than a line that is itself already past end of life. ISC's current lines on our BIND 9 page are 9.18, 9.20 and the 9.21 development branch. The advisory lists port 53 among the ports the actors scan.
Pulse Connect Secure 8.2, 8.3 and 9.0 (CVE-2019-11510). The product is now Ivanti Connect Secure, and all three named lines are long gone: 8.2 reached end of life on July 11, 2018, 8.3 on October 11, 2019 and 9.0 on October 30, 2020. The 9.1 line that followed them ended on December 31, 2024. The supported releases in our data are the 22.7 and later 22.x lines and the 25.1 releases, all on our Ivanti Connect Secure page. This is the product the advisory's VPN persistence sentence is most likely to touch, and a VPN gateway is the one device on this list that is reachable from the internet by design.
GitLab (CVE-2021-22205, "All versions starting from 11.9" as the advisory prints it). GitLab's data shows each minor release reaching end of life about three months after it ships, so every 11.x, 12.x and 13.x release is far outside support: 13.10, the oldest line we carry, ended on June 22, 2021. The CVE is a remote code execution flaw in both Community and Enterprise Editions. The replacement is a current GitLab release from our GitLab page; a self-managed instance several major versions behind needs GitLab's documented upgrade path rather than a single jump.
ONLYOFFICE DocumentServer 5.1.5 through 5.6.2 (CVE-2021-3199). We do not track ONLYOFFICE, so we state no end-of-life date for it. The advisory's version range is a 5.x range from a product now several major versions on; a DocumentServer in that range has not been updated since the CVE was assigned.
GNU Bash through 4.3 bash43-026 (CVE-2014-6278). We do not track GNU Bash as a product; it ships inside operating systems and is patched through them. A host whose Bash is still at the patch level the advisory names has not taken an operating-system update since the CVE's year, which makes the operating system, not the shell, the end-of-life product to replace. Our EOL Checker covers the Linux distributions that ship it.
Strapi 4 (CVE-2023-22894, up to 4.5.5). The 4 line reached end of life on June 9, 2026, the most recent end-of-life date on this list. Strapi 5 is the supported line on our Strapi page. A Strapi 4 instance at 4.5.5 or earlier is inside the advisory's range; later 4.x releases fixed this CVE, but the 4 line no longer receives fixes for whatever comes next, so the move to 5 is the path that stays closed.
What to do
- Inventory against the eight lines, by version. Struts 2.3.x, ProFTPD 1.3.5, BIND 9.9 and 9.10, Pulse Connect Secure 8.2, 8.3 and 9.0 (any Pulse or Ivanti Connect Secure below the supported 22.x lines), GitLab below a current release, ONLYOFFICE DocumentServer 5.x, Strapi 4.5.5 and earlier, and any host whose Bash predates the 2014 fixes. Our EOL Checker and API return the end-of-life status for the lines we track; the Exploited and unpatchable feed lists products that combine a KEV entry with the end of vendor fixes.
- Replace, do not wait for a patch. For every tracked line above, the vendor's fix for the CVE shipped in a later build of the same line, and that line is now itself past end of life; the only supported path is a current line. The advisory's sentence is the plan: replace end-of-life products with supported alternatives that are included in vendor support plans.
- Federal civilian agencies: the KEV due date for the five new entries is October 11, 2026. Three days from the entry. For an end-of-life line, remediation means removal or replacement, and the due date is met when the vulnerable version is gone from the network, not when a ticket is opened.
- Isolate what cannot move yet. The advisory's own mitigations for this case: disable unused services and ports (it names automatic configuration, remote access and file sharing protocols), segment the network so a compromised device reaches nothing else, review web application access logs for directory traversal and command injection attempts, and require MFA on webmail, VPNs and accounts that reach critical systems.
- Hunt. The advisory asks network defenders to hunt for this activity and publishes indicators of compromise in STIX JSON and XML on the advisory page, together with the scanning tools, the MicroScan application and the XSS payload the FBI recovered.
Frequently Asked Questions
What is CISA advisory AA26-281A?
AA26-281A is a joint cybersecurity advisory released on October 8, 2026 by the FBI, CISA, NSA, the UK's NCSC, Australia's ASD ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC and Spain's CNI. Its title is Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data. It describes threat actors enabled by the Integrity Technology Group, a China-based company with links to the Chinese government, and lists eight CVEs the actors successfully exploited. Among its mitigations is a one-line instruction: replace end-of-life products with supported alternatives that are included in vendor support plans.
Which CVEs does AA26-281A list, and which are new to the KEV catalog?
Eight: CVE-2014-6278 (GNU Bash), CVE-2015-3306 (ProFTPD 1.3.5), CVE-2015-5477 (ISC BIND 9.9 and 9.10), CVE-2016-3081 (Apache Struts 2.3), CVE-2019-11510 (Pulse Connect Secure 8.2, 8.3 and 9.0), CVE-2021-22205 (GitLab), CVE-2021-3199 (ONLYOFFICE DocumentServer) and CVE-2023-22894 (Strapi). The advisory marks five of them with an asterisk as newly added to CISA's Known Exploited Vulnerabilities catalog: the ProFTPD, BIND, Struts, ONLYOFFICE and Strapi entries. CISA added those five on October 8, 2026, the day the advisory was released, each with a due date of October 11, 2026 for federal civilian agencies. The Bash, Pulse Connect Secure and GitLab entries were already in the catalog.
Which of the products in AA26-281A are end of life?
Every line the advisory names that we track is past its end-of-life date. Apache Struts 2.3 reached end of life on May 14, 2019; ProFTPD 1.3.5 on July 20, 2020; Pulse Connect Secure 9.0, the newest of the three Pulse lines named, on October 30, 2020; and Strapi 4, the line that contains every affected Strapi version, on June 9, 2026. GitLab's oldest line in our data, 13.10, ended on June 22, 2021, and every earlier release inside the advisory's range is older still. We do not carry lifecycle dates for GNU Bash, for BIND 9.9 and 9.10, or for ONLYOFFICE DocumentServer, so we make no end-of-life claim for those three.
What does the October 11, 2026 KEV due date mean?
Every entry in CISA's Known Exploited Vulnerabilities catalog carries a date by which federal civilian executive branch agencies must remediate it. The five entries added from this advisory carry a due date three days after they were added, the short window CISA reserves for its most urgent entries. For these products a later build on the same line fixed the CVE years ago, but that line is itself past end of life and receives no further fixes, so the lasting way to meet the date is to replace the product rather than patch it. Organizations outside the US federal government are not bound by the date, but CISA publishes the catalog for every organization to use as a remediation priority list, and the advisory's authoring agencies ask all network defenders to hunt for this activity.
Why does the advisory say replace rather than patch?
Because a product that has left vendor support receives no further fixes: patching it closes yesterday's CVE and nothing after it. Every CVE on the list is years old and the version ranges the advisory prints describe builds the vendors moved past long ago; a system that is still exploitable through one of them is running a version its vendor stopped maintaining. Upgrading in place to a supported line is the replacement the advisory calls for: Struts 2.3 to a supported Struts line, ProFTPD 1.3.5 to the current 1.3.x release, Strapi 4 to Strapi 5, GitLab to a current release, and Pulse Connect Secure 8.x or 9.0 to a supported Ivanti Connect Secure release. Where no supported successor fits, the advisory's other mitigations, disabling unused services and ports and segmenting the network, are the controls that remain.
Related
- AA26-281A on cisa.gov — the advisory, with Appendix B (the CVE table) and the STIX indicators
- Ivanti Connect Secure — every Pulse and Ivanti Connect Secure line with its live status and EOL Risk Score
- Apache Struts, ProFTPD, GitLab, Strapi, BIND 9 — the other lifecycle pages behind the table
- Exploited and unpatchable — products with a CISA KEV entry and no remaining vendor fix
- ASD on legacy technology — another agency's case that end-of-life systems are the first to fall
- CISA BOD 26-04 and BOD 26-02 explained — how KEV due dates bind federal agencies
- How we verify our dates — the rules every number on this site is held to