The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.

The vulnerabilities in question are listed below –

CVE-2015-3306 (CVSS score: 10.0) – An improper access control vulnerability in ProFTPD that could allow