Critical ProFTPD 1.3.5 flaw allows unauthenticated file read and write, and is under active exploitation
CISA has confirmed active exploitation of CVE-2015-3306, a CVSS 10 flaw in ProFTPD 1.3.5's mod_copy module that lets a remote attacker read and write arbitrary files on the server. It affects ProFTPD installations and the versions shipped with Debian, Fedora, openSUSE Tumbleweed and SUSE Linux Enterprise Server.
What happened
On 8 October 2026 CISA added CVE-2015-3306 to its Known Exploited Vulnerabilities (KEV) catalogue, with a remediation deadline for US federal agencies of 11 October 2026. In other words, there is confirmed evidence of real-world attacks abusing this flaw.
The vulnerability lies in the mod_copy module of ProFTPD 1.3.5. According to the description published by NVD, a remote attacker can use the SITE CPFR and SITE CPTO commands to read and write arbitrary files on the system. Crucially, these commands can be issued without first authenticating to the FTP service.
The severity is as high as it gets: CVSS 3.1 score of 10.0 (critical), network attack vector, low complexity, no privileges or user interaction required, and scope change. In practice, the ability to write arbitrary files on a server often leads to code execution and full control of the machine.
Who is affected
According to NVD data, the affected technologies are:
- ProFTPD 1.3.5 (standalone or self-compiled installations)
- Debian Linux
- Fedora
- openSUSE Tumbleweed
- SUSE Linux Enterprise Server
Exploitation status
Beyond its presence in the KEV catalogue, public exploit code is widely available: the flaw is published on Exploit-DB, has a Metasploit module (making the attack reliable and within anyone's reach), a Nuclei template (allowing vulnerable servers to be found automatically and at scale), and proof-of-concept code on GitHub, the latter unverified.
FIRST estimates a 98% probability of exploitation over the next 30 days, placing it in the 100th percentile: among the vulnerabilities with the highest immediate risk of all those known. Use in ransomware campaigns is listed as unknown.
What to do
This calls for action within hours or days, not weeks. Concrete steps:
- Inventory your organisation's FTP servers and check whether any run ProFTPD 1.3.5.
- Apply the proftpd package updates published by your distribution (Debian, Fedora, openSUSE, SUSE). The available references include update announcements from Fedora and openSUSE; the exact fixed versions are not detailed in the data reviewed, so confirm them against your distribution's repository.
- If immediate patching is not possible, disable the mod_copy module in the server configuration, since that is where the flaw resides.
- Restrict access to the FTP port from the internet using firewalls or a VPN: public exposure is what makes this flaw so dangerous.
- Review service logs for unexpected SITE CPFR and SITE CPTO commands, and check for new or modified files in directories reachable by the web service, in case a compromise has already occurred.
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2015-3306 | Critical (10) | ⚠ Active exploitation | 5/18/2015 | Analyzed |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.