Daily intelligence / OT · ICS · BASIssue 2026.10.11
Today's lead signal

Active threat: ProFTPD Improper Access Control Vulnerability

5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Read the brief
Sunday, October 11, 2026 27 feed items analyzed Source-grounded, analyst-ready
Active exploitation05Authoritative evidence only
Critical07CVSS 9.0+ or equivalent
High priority05Filtered for OT relevance
Evidence sourcesT1/2Government, vendors, research

Curating trusted cybersecurity reporting…

OT Weekly Brief

The week's signal, delivered.

Confirmed exploitation, industrial relevance and safe next actions — distilled into one source-linked briefing every Friday.

Priority queue

What deserves attention now.

Ranked by exploit evidence, severity and industrial relevance.

12 of 12 intelligence items
Since the previous editionOnly material source, severity and exploitation changes are highlighted.
7 new0 updated7 out of queue
01
ACTIVECVEOT relevance 15%EPSS 99.5%

CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEVActive Exploitation
CISA KEV
02
ACTIVECVEOT relevance 15%EPSS 99.4%

CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEVActive Exploitation
CISA KEV
03
ACTIVECVEOT relevance 15%EPSS 96.1%

CVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEVActive Exploitation
CISA KEV
04
ACTIVECVEOT relevance 15%EPSS 19.4%

CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEVActive Exploitation
CISA KEV
05
ACTIVECVEOT relevance 15%EPSS 3.6%

CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEVActive Exploitation
CISA KEV
06
CRITICALCVEOT relevance 15%New todayCVSS 10.0

CVE-2026-42696: Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.

Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.

Not present in the previous daily edition.

CVENVD
NIST NVD
07
CRITICALCVEOT relevance 15%New todayCVSS 9.8

CVE-2026-105892: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.

Not present in the previous daily edition.

CVENVD
NIST NVD
08
CRITICALCVEOT relevance 15%New todayCVSS 9.8

CVE-2026-106610: Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This is

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.

Not present in the previous daily edition.

CVENVD
NIST NVD
09
CRITICALCVEOT relevance 15%New todayCVSS 9.8

CVE-2026-108551: openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject Java

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are imported or service methods called.

Not present in the previous daily edition.

CVENVD
NIST NVD
10
CRITICALCVEOT relevance 15%New todayCVSS 9.8

CVE-2026-108598: Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via un

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

Not present in the previous daily edition.

CVENVD
NIST NVD
11
CRITICALCVEOT relevance 15%New todayCVSS 9.8

CVE-2026-39801: Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.

Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.

Not present in the previous daily edition.

CVENVD
NIST NVD
12
CRITICALCVEOT relevance 15%New todayCVSS 9.8

CVE-2026-104398: Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Objec

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.

Not present in the previous daily edition.

CVENVD
NIST NVD
Global signal map

Context, not threat theater.

Advisory locations do not imply attacker attribution.
Selected regionEscalate
United States

Active Siemens S7 targeting

Signals in queue04
Signal analytics

Separate movement from noise.

Priority trend

Escalated signals

Critical High
Collection volume

Feed items analyzed

163Total items
in selected period

27 is today's edition. 163 is the cumulative volume across 7 available editions in this view.

OT research lens

Patterns worth investigating.

7 editions analyzed
Most represented vendors

Zammad GmbH8

Citrix6

ProFTPD3

Asset focus

Building automation39

Remote access4

Historian1

Correlation coverage

57CVEs

4ICS / vendor advisories

Movement

0signals versus prior 7 editions

Volume change is a research cue, not a risk score.
PDF bulletin builder

Turn the signal into a briefing.

Create a clean, source-linked bulletin for any day, trailing week or calendar month. The highest-priority news, CVEs and vendor advisories are ranked automatically.

Build a PDF report
OT action model

From headline to plant-floor decision.

01Validate exposureAsset, version, reachability, internet path and remote access.
02Confirm exploit evidenceKEV, government warning, vendor status and credible research.
03Apply process contextSafety, availability, redundancy and maintenance windows.
04Mitigate safelySegment, restrict, monitor, patch or compensate.
Evidence pipeline

Built for a reliable daily refresh.

Primary feeds and curated OT research move through a transparent evidence gate before any signal reaches the brief.

Connected now
CISA KEVCISA ICSNIST NVDCisco PSIRTSiemens ProductCERTSecurityWeek ICS/OTFIRST EPSS
01Collect02Normalize03Score04Publish