« All news

Follow-up · active exploitationCritical

Critical ProFTPD 1.3.5 flaw allows unauthenticated file read and write, and is under active exploitation

CISA has confirmed active exploitation of CVE-2015-3306, a CVSS 10 flaw in ProFTPD 1.3.5's mod_copy module that lets a remote attacker read and write arbitrary files on the server. It affects ProFTPD installations and the versions shipped with Debian, Fedora, openSUSE Tumbleweed and SUSE Linux Enterprise Server.

What happened

On 8 October 2026 CISA added CVE-2015-3306 to its Known Exploited Vulnerabilities (KEV) catalogue, with a remediation deadline for US federal agencies of 11 October 2026. In other words, there is confirmed evidence of real-world attacks abusing this flaw.

The vulnerability lies in the mod_copy module of ProFTPD 1.3.5. According to the description published by NVD, a remote attacker can use the SITE CPFR and SITE CPTO commands to read and write arbitrary files on the system. Crucially, these commands can be issued without first authenticating to the FTP service.

The severity is as high as it gets: CVSS 3.1 score of 10.0 (critical), network attack vector, low complexity, no privileges or user interaction required, and scope change. In practice, the ability to write arbitrary files on a server often leads to code execution and full control of the machine.

Who is affected

According to NVD data, the affected technologies are:

Exploitation status

Beyond its presence in the KEV catalogue, public exploit code is widely available: the flaw is published on Exploit-DB, has a Metasploit module (making the attack reliable and within anyone's reach), a Nuclei template (allowing vulnerable servers to be found automatically and at scale), and proof-of-concept code on GitHub, the latter unverified.

FIRST estimates a 98% probability of exploitation over the next 30 days, placing it in the 100th percentile: among the vulnerabilities with the highest immediate risk of all those known. Use in ransomware campaigns is listed as unknown.

What to do

This calls for action within hours or days, not weeks. Concrete steps:

Affected technologies

ProFTPDDebian LinuxFedoraopenSUSE TumbleweedSUSE Linux Enterprise Server

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2015-3306Critical (10)⚠ Active exploitation5/18/2015Analyzed

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.