Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Decade-Old Bugs Still Being Exploited in 2026: ProFTPD, BIND, Struts, ONLYOFFICE, DD-WRT & More

High CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894, CVE-2021-27137, CVE-2019-1068, CVE-2021-23758, CVE-2015-3246, CVE-2015-5287, CVE-2008-4128 — CISA added a batch of 2008-2023 vulnerabilities to its exploited list this summer, including ProFTPD mod_copy, BIND TKEY, Apache Struts S2-032, ONLYOFFICE, DD-WRT UPnP and SQL Server. Why old bugs keep working, and how to find them on your network.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Some of 2026's newly confirmed exploited vulnerabilities are 10 to 18 years old. Attackers scan the whole internet for forgotten FTP servers, ancient DNS servers, abandoned Struts apps and old router firmware, because there are still plenty. Every fix on this page has existed for years, so the real job is finding the old box nobody remembers.

OldestCVE-2008-4128: Cisco IOS 12.4 CSRF on the 871 router (KEV 2026-07-13)
Remote, no authProFTPD mod_copy file read/write, BIND TKEY crash, Struts S2-032 RCE, ONLYOFFICE upload RCE, DD-WRT UPnP overflow
Local rootlibuser/userhelper (CVE-2015-3246), ABRT symlink (CVE-2015-5287)
OtherSQL Server CVE-2019-1068 RCE, AjaxPro.2 .NET deserialization, Strapi user-data leak
Added to KEVBetween 2026-07-13 and 2026-10-08
FixLong available. Upgrade, replace, or decommission.

Why old bugs still work

Attackers don’t need zero-days when a quick internet-wide scan turns up thousands of servers that haven’t been updated since the Obama administration. Appliances get installed and forgotten, a contractor’s test server stays online for a decade, a router is never flashed after the day it was set up. When CISA adds a 2015 CVE to its exploited list in 2026, it’s because someone was caught using it against a real target this year.

The list

CVEProductWhat it doesFixed in
CVE-2015-3306ProFTPD 1.3.5 (mod_copy)SITE CPFR/SITE CPTO let anyone copy files on the server without logging in, which in practice means dropping a web shell. Public Metasploit module.ProFTPD 1.3.5a / 1.3.6+
CVE-2015-5477ISC BIND 9A single TKEY query crashes named: DNS down on demand.9.9.7-P2 / 9.10.2-P3 (2015); any current BIND
CVE-2016-3081Apache Struts 2.3.x (S2-032)Remote code execution when Dynamic Method Invocation is enabled.Struts 2.3.20.3 / 2.3.24.3 / 2.3.28.1+; Struts 2.3 is long EOL
CVE-2021-3199ONLYOFFICE Document Server < 5.6.3Directory traversal in image upload → remote code execution (when JWT is used).5.6.3+
CVE-2021-27137DD-WRT (UPnP)Buffer overflow in the UPnP SSDP handler; only if UPnP is enabled (off by default, LAN-only by default).DD-WRT build 45724+
CVE-2019-1068SQL Server 2014 SP2, 2016 SP1/SP2, 2017Remote code execution in internal function handling.July 2019 security updates
CVE-2021-23758AjaxPro.2 (.NET library)Deserialization of arbitrary .NET classes → RCE in web apps that embed it.Patched upstream; remove or update the library
CVE-2023-22894Strapi ≤ 4.5.5Admin-panel users can extract password hashes and reset tokens via query filters.Strapi 4.8.0+
CVE-2015-3246libuser / userhelper (RHEL/CentOS 6–7 era)Combined with CVE-2015-3245, local users gain root.libuser 0.56.13-8 / 0.60-7
CVE-2015-5287ABRT (Fedora/RHEL bug reporter)Symlink attack on a predictable coredump path → local root.ABRT 2.7.1
CVE-2008-4128Cisco IOS 12.4 HTTP admin (871 ISR)CSRF lets a malicious web page run commands on the router through an admin’s browser.Hardware/software long EOL: replace

How to find these on your network

  • Scan yourself first. From outside, use a service like Shodan or Censys on your public IPs; from inside, an nmap service scan:
    nmap -sV -p 21,53,80,443,1433,8080,8443 192.168.1.0/24
    It will show FTP banners like ProFTPD 1.3.5, BIND versions (if not hidden), and old web servers.
  • Check DNS servers: dig @your-dns-server version.bind chaos txt (if it answers with a 9.9/9.10 version, it’s ancient).
  • Inventory SQL Server instances: SELECT @@VERSION; on each; anything 2014/2016 SP1/2017 without 2019+ updates is exposed, and 2014 is out of support entirely.
  • Grep your web apps for old libraries: struts2-core-2.3 JARs, AjaxPro.2.dll, old Strapi package.json versions.
  • Router firmware: log in to every router/AP you own (including the one in the back office) and check the firmware date.

Fixing it

  • Update or upgrade where the product is still maintained (ProFTPD, BIND, ONLYOFFICE, Strapi, DD-WRT, SQL Server).
  • Replace what’s end of life (Struts 2.3 apps, Cisco 871s, SQL Server 2014). No patch is coming.
  • Turn off what you don’t need: plain FTP (use SFTP), UPnP on routers, recursive DNS open to the internet.
  • Decommission the box nobody can explain. If no one knows what it does, it’s probably not doing anything you need, and it’s certainly not being patched.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories