What happened

On October 8, 2026, the FBI, CISA, NSA and agencies from the UK, Australia, Canada, Japan, New Zealand and Spain published joint advisory AA26-281A on a scanning and exploitation platform called MicroScan. The advisory ties the activity to Integrity Technology Group and says it is "consistent with" groups tracked as Flax Typhoon, Ethereal Panda and RedJuliett. It has been observed "since at least mid-January 2021". The actors focus their scanning on a handful of ports, starting with port 21 (FTP). The advisory's table of successfully exploited CVEs includes CVE-2015-3306 in ProFTPD 1.3.5, marked as newly added to the KEV catalog. CISA added it the same day, together with four other older flaws, with a federal deadline of October 11.

The bug itself is from 2015. ProFTPD's bug 4169 describes it: mod_copy allowed its SITE CPFR and SITE CPTO commands to be used by unauthenticated clients. Vadim Melihow reported it, and ProFTPD fixed it in 1.3.5a, released May 27, 2015, and in 1.3.6rc1. NVD scores it CVSS 3.1 10.0. Exploit code has been public since April 2015. A Metasploit module, "ProFTPD 1.3.5 Mod_Copy Command Execution," copies a PHP payload into the web root (/var/www by default) and runs it.

Why it matters if you run public infrastructure

Nobody installs ProFTPD 1.3.5 today. These servers are the ones that never got touched again: an old web host still offering FTP, a box set up for a file drop years ago, a forgotten appliance. That is exactly what an automated platform scanning port 21 finds. The flaw needs no account. On a server that also serves PHP from a known directory, copying a file into the web root is a straight path to running code. The advisory lists the impact it observed as unauthorized read. Upstream does not compile mod_copy by default, but Debian's packages load it in their stock configuration, so many Linux installs have it switched on.

What to check this week

  1. Find every FTP service you expose, including on hosts you think of as web servers, and note the greeting each one sends on connect.
  2. Check the version with proftpd -v on the server. Upstream 1.3.5 is affected; 1.3.5a, 1.3.6rc1 and later are fixed. Distribution packages can carry the fix under the old number. Debian's fixed jessie package, for example, is 1.3.5-1.1+deb8u1, so check the package version too.
  3. Check whether mod_copy is reachable. Connect without logging in and send SITE CPFR /etc/passwd. A 350 reply means the server accepts the command from anonymous clients. The command only names a source file; it does not copy anything.
  4. Upgrade, or turn mod_copy off. On a server that cannot be upgraded today, comment out LoadModule mod_copy.c (in Debian's modules.conf) and restart. Better still, retire the server: the joint advisory's advice is to replace end-of-life products with supported ones.
  5. Look for signs of compromise on any server that was exposed: unexpected .php files in the web root, and SITE CPFR or SITE CPTO commands from unauthenticated sessions in the FTP logs.
  6. Ask whether it needs FTP at all. Most of these services can be switched off or replaced with SFTP behind an allowlist.

How Attack Surface Scan covers this

Attack Surface Scan reads the greeting that FTP servers send on connect on hosts under your verified domains, including hosts found through certificate transparency logs, and recognizes ProFTPD. When the greeting includes the version, we match it against NVD's affected range (here, exactly 1.3.5), and KEV-listed CVEs like this one rank first. A distribution package with the fix backported still announces 1.3.5, so treat a match as "check this server," not proof. When the version is hidden, we report the product but do not guess which CVEs apply. We do not send SITE commands or exploit traffic. See Vulnerability matching for the details.

Sources