Spain signs international advisory on Integrity Technology Group-linked attacks: five legacy vulnerabilities return to the KEV catalogue
Agencies from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States have published a joint advisory on attacks facilitated by the Chinese firm Integrity Technology Group. On the same day, CISA added five flaws dating from 2015 to 2023 to its Known Exploited Vulnerabilities catalogue.

News summary
On 8 October 2026, CISA added five vulnerabilities published between 2015 and 2023 to its Known Exploited Vulnerabilities (KEV) catalogue: CVE-2015-3306 in ProFTPD, CVE-2015-5477 in ISC BIND, CVE-2016-3081 in Apache Struts, CVE-2021-3199 in ONLYOFFICE Docs, and CVE-2023-22894 in Strapi.
According to Xploitwire, these additions coincide with a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States concerning operations facilitated by Integrity Technology Group, a China-based cybersecurity firm. The advisory links these operations to eight vulnerabilities, including these five.
What is striking is not the novelty of the flaws, but their age. FTP and DNS servers or web applications installed years ago and forgotten remain an entry point. Furthermore, some of these CVEs lack a CVSS v3 score, meaning many tools display them with low priority.
For a Spanish company, the takeaway is simple: the asset inventory must also include what no one remembers installing. An exposed, unmaintained service can become a high-priority target.
Source: Xploitwire — 9 October 2026
Frequently Asked Questions
- Why are vulnerabilities from 2015 being added now?
- Because there is evidence they are being exploited in current attacks. The KEV catalogue reflects real-world exploitation, not the flaw's publication date.
- What is Spain's role in the advisory?
- According to the published information, Spain is one of the seven signatories of the joint advisory.
Concepts mentioned in this article: Cybersecurity
You can't protect what you don't have in your inventory. At Seintec, we review your attack surface, decommission unnecessary assets, and prioritise patching based on real-world exploitation. Speak with our cybersecurity team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.