Cyber & AI intelligence
Wasteland.
Briefs indexed3090
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2015-3306 2026-10-08

ProFTPD mod_copy Flaw CVE-2015-3306 Added to CISA KEV With a Three-Day Deadline

"CISA has added CVE-2015-3306 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The flaw is a decade-old access control bug in ProFTPD 1.3.5 that lets remote attackers read and write…"

CISA has added CVE-2015-3306 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The flaw is a decade-old access control bug in ProFTPD 1.3.5 that lets remote attackers read and write arbitrary files.

What Is It

CVE-2015-3306 is an improper access control vulnerability (CWE-284) in the mod_copy module of ProFTPD 1.3.5. According to NVD, remote attackers can use the site cpfr and site cpto commands to read and write arbitrary files. NVD first published the CVE on May 18, 2015.

Why It Matters

CISA added the flaw to the KEV catalog on 2026-10-08, which confirms it is being actively exploited. CISA's SSVC assessment also lists exploitation as active and technical impact as total.

What's Vulnerable

CISA notes that the flaw could affect an open-source component, third-party library, protocol or proprietary implementation used by other products. Downstream products that embed ProFTPD may also be exposed.

Patch Status

CISA's required action is to apply mitigations according to vendor instructions. The KEV entry points to BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. BOD 26-04 binds federal civilian executive branch agencies. Other organizations can use it as guidance. If no mitigations are available, CISA's listed action is to follow BOD 26-04 guidance for cloud services or stop using the product. CISA also recommends evaluating each asset's internet exposure. The federal due date is 2026-10-11.

Debian (DSA-3263), Fedora and openSUSE published distribution advisories in 2015. Check your distribution's package status and the vendor's guidance at proftpd.org.

Sources