PDF briefing studio

Prepare a decision-ready brief.

Select a reporting window. Top cyber news, vulnerabilities and CISA ICS advisories are ranked automatically.

OT Daily BriefIndustrial cyber intelligence
Source-groundedday decision brief
OT / ICS / BAS intelligenceDecision brief / 2026.10.11
Intelligence for industrial defenders

Daily
cyber risk brief.

October 11, 2026

This edition / priority focus

ProFTPD Improper Access Control Vulnerability

Threat posture5 active signals
Scope10 selected signals
Source-grounded intelligence / selected reporting windowEvidence / exposure / operational context
Analyzed27Feed items
Selected10Relevant signals
Critical7Priority items
Active5Exploitation signals
Sources2Referenced
Vendor concentrationWithin vendors
ProFTPD1
ISC1
Apache1
ONLYOFFICE1
Technology concentrationWithin technologies
ProFTPD1
BIND1
Struts1
Docs1
Period pulseLatest reporting movement
11
High / Critical / Active exploitation
Editorial movementSelected edition
Active threat: ProFTPD Improper Access Control Vulnerability

5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

27 analyzed

ProFTPD Improper Access Control Vulnerability

5 items have authoritative exploitation evidence and should move first through exposure validation. Current concentration is around ProFTPD, ISC, Apache; use the product context in the queue to compare it with the asset inventory.

5 active exploitation signals5 critical items1 edition reviewed
Now
Validate active exposure

Confirm asset, version, reachability and compensating controls for ProFTPD.

Next window
Plan safe remediation

Review maintenance constraints and vendor guidance for CVE-2026-42696: Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions..

Active threat: ProFTPD Improper Access Control Vulnerability

5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

01
ACTIVECVEOT relevance 15%EPSS 99.5%

CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ProFTPD / ProFTPDCISA KEV
02
ACTIVECVEOT relevance 15%EPSS 99.4%

CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ISC / BINDCISA KEV
03
ACTIVECVEOT relevance 15%EPSS 96.1%

CVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Apache / StrutsCISA KEV
04
ACTIVECVEOT relevance 15%EPSS 19.4%

CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ONLYOFFICE / DocsCISA KEV
05
ACTIVECVEOT relevance 15%EPSS 3.6%

CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Strapi / StrapiCISA KEV
06
CRITICALCVEOT relevance 15%CVSS 10.0

CVE-2026-42696: Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.

Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.

Industrial ecosystemNIST NVD
07
CRITICALCVEOT relevance 15%CVSS 9.8

CVE-2026-105892: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.

Industrial ecosystemNIST NVD
08
CRITICALCVEOT relevance 15%CVSS 9.8

CVE-2026-106610: Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This is

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.

Industrial ecosystemNIST NVD
Security newsBleepingComputer

Nippon Columbia malware incident exposes 8.6 million karaoke fan records

Daiichi Kosho, a major Japanese entertainment system maker, disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7 million customer and employee records. [...]

BleepingComputer
Methodology / transparent by design

Evidence first.
Context always.

A triage aid for exposure validation and operational review.

Exploit evidence
OT relevance
Severity
Source confidence
+10EPSS acceleratorMaximum additional points
100-point base model + up to 10 predictive points. The score is not a percentage of plant risk.
Evidence standard

Active exploitation is reserved for authoritative confirmation. CVSS alone is never treated as operational risk; exposure, process context and safe remediation remain essential.