High CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894, CVE-2021-27137, CVE-2019-1068, CVE-2021-23758, CVE-2015-3246, CVE-2015-5287, CVE-2008-4128 — CISA added a batch of 2008-2023 vulnerabilities to its exploited list this summer, including ProFTPD mod_copy, BIND TKEY, Apache Struts S2-032, ONLYOFFICE, DD-WRT UPnP and SQL Server. Why old bugs keep working, and how to find them on your network.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Some of 2026's newly confirmed exploited vulnerabilities are 10 to 18 years old. Attackers scan the whole internet for forgotten FTP servers, ancient DNS servers, abandoned Struts apps and old router firmware, because there are still plenty. Every fix on this page has existed for years, so the real job is finding the old box nobody remembers.
| Oldest | CVE-2008-4128: Cisco IOS 12.4 CSRF on the 871 router (KEV 2026-07-13) |
|---|---|
| Remote, no auth | ProFTPD mod_copy file read/write, BIND TKEY crash, Struts S2-032 RCE, ONLYOFFICE upload RCE, DD-WRT UPnP overflow |
| Local root | libuser/userhelper (CVE-2015-3246), ABRT symlink (CVE-2015-5287) |
| Other | SQL Server CVE-2019-1068 RCE, AjaxPro.2 .NET deserialization, Strapi user-data leak |
| Added to KEV | Between 2026-07-13 and 2026-10-08 |
| Fix | Long available. Upgrade, replace, or decommission. |
Attackers don’t need zero-days when a quick internet-wide scan turns up thousands of servers that haven’t been updated since the Obama administration. Appliances get installed and forgotten, a contractor’s test server stays online for a decade, a router is never flashed after the day it was set up. When CISA adds a 2015 CVE to its exploited list in 2026, it’s because someone was caught using it against a real target this year.
| CVE | Product | What it does | Fixed in |
|---|---|---|---|
| CVE-2015-3306 | ProFTPD 1.3.5 (mod_copy) | SITE CPFR/SITE CPTO let anyone copy files on the server without logging in, which in practice means dropping a web shell. Public Metasploit module. | ProFTPD 1.3.5a / 1.3.6+ |
| CVE-2015-5477 | ISC BIND 9 | A single TKEY query crashes named: DNS down on demand. | 9.9.7-P2 / 9.10.2-P3 (2015); any current BIND |
| CVE-2016-3081 | Apache Struts 2.3.x (S2-032) | Remote code execution when Dynamic Method Invocation is enabled. | Struts 2.3.20.3 / 2.3.24.3 / 2.3.28.1+; Struts 2.3 is long EOL |
| CVE-2021-3199 | ONLYOFFICE Document Server < 5.6.3 | Directory traversal in image upload → remote code execution (when JWT is used). | 5.6.3+ |
| CVE-2021-27137 | DD-WRT (UPnP) | Buffer overflow in the UPnP SSDP handler; only if UPnP is enabled (off by default, LAN-only by default). | DD-WRT build 45724+ |
| CVE-2019-1068 | SQL Server 2014 SP2, 2016 SP1/SP2, 2017 | Remote code execution in internal function handling. | July 2019 security updates |
| CVE-2021-23758 | AjaxPro.2 (.NET library) | Deserialization of arbitrary .NET classes → RCE in web apps that embed it. | Patched upstream; remove or update the library |
| CVE-2023-22894 | Strapi ≤ 4.5.5 | Admin-panel users can extract password hashes and reset tokens via query filters. | Strapi 4.8.0+ |
| CVE-2015-3246 | libuser / userhelper (RHEL/CentOS 6–7 era) | Combined with CVE-2015-3245, local users gain root. | libuser 0.56.13-8 / 0.60-7 |
| CVE-2015-5287 | ABRT (Fedora/RHEL bug reporter) | Symlink attack on a predictable coredump path → local root. | ABRT 2.7.1 |
| CVE-2008-4128 | Cisco IOS 12.4 HTTP admin (871 ISR) | CSRF lets a malicious web page run commands on the router through an admin’s browser. | Hardware/software long EOL: replace |
nmap -sV -p 21,53,80,443,1433,8080,8443 192.168.1.0/24
It will show FTP banners like ProFTPD 1.3.5, BIND versions (if not hidden), and old web servers.dig @your-dns-server version.bind chaos txt (if it answers with a 9.9/9.10 version, it’s ancient).SELECT @@VERSION; on each; anything 2014/2016 SP1/2017 without 2019+ updates is exposed, and 2014 is out of support entirely.struts2-core-2.3 JARs, AjaxPro.2.dll, old Strapi package.json versions.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.