The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
SITE CPFR and SITE CPTO commands./.. sequence in an image upload parameter to potentially execute code remotely.method: prefixes when Dynamic Method Invocation is enabled.The five vulnerabilities have been added to a broader list of flaws linked to cyber operations attributed to China-linked actors associated with Integrity Technology Group, a China-based cybersecurity company. The update coincides with a joint advisory issued by Australia, Canada, Japan, New Zealand, Spain, the United Kingdom and the United States. U.S. authorities have also taken action against tools associated with Integrity Tech and used in cyber espionage operations.
The activity reportedly involved the exploitation of eight vulnerabilities, including the five listed above, to gain initial access to targeted networks and steal sensitive information. The attackers used scanning tools, cross-site scripting (XSS) and password-spraying attacks against Microsoft Exchange servers. They also relied on VPN software to maintain access and scripts to extract emails and credentials.
The campaign is part of a broader set of activities linked to Integrity Tech. The U.S. Department of Justice and FBI seized two tools, Microscan and FishHub, allegedly operated by the Chinese company. Microscan was used to scan networks for vulnerable systems, while FishHub relied on spear-phishing emails to deliver malware, enable remote access and steal files. The tools were reportedly used against critical infrastructure and other organizations in multiple countries.
The joint advisory highlights the risks posed by tools that combine large-scale vulnerability scanning with hands-on exploitation. The coordinated action by seven countries and the U.S. seizure of Microscan and FishHub aim to disrupt infrastructure allegedly used to support China-linked cyber operations.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaws by October 11, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)