The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, covering flaws in Apache Struts, ISC BIND, ProFTPD, ONLYOFFICE Docs, and Strapi — a mix of components that will force many Hong Kong IT teams to look beyond their usual patching shortlist.
Security Affairs reported the additions on 22 April. Per-vulnerability remediation deadlines are set in the official CISA KEV catalog, which teams should consult directly rather than rely on secondary reporting.
What HK IT teams should do now
1. Audit Apache Struts and ProFTPD first. Struts carries the highest remediation priority. Its history — most notably the 2017 Equifax breach, and a long track record of internet-facing exploits being weaponised within days of disclosure — means any Struts instance that lags a KEV-flagged patch should be treated as an incident, not a backlog item. Legacy FTP is the other priority-one item: ProFTPD deployments are frequently self-hosted, lightly monitored, and invisible to vulnerability-management programmes built around web applications and cloud workloads.
2. Alert BIND and DNS administrators. A KEV-listed BIND flaw means the domain name system itself is in scope. If your DNS is run in-house or by a managed provider using ISC software, raise a targeted ticket with the DNS team — this class of service rarely appears on the asset registers that drive patch cycles, and a BIND flaw carries availability risk well beyond confidentiality.
3. Check ONLYOFFICE Docs and Strapi. Document-collaboration and headless-CMS platforms both sit on internal networks with broad user access, and both are commonly deployed via containers, where image refreshes can quietly lag the upstream fix.
Why KEV matters beyond Washington
The KEV catalog is a U.S. government list, but it has become a de facto international baseline — a natural reference point for any organisation that needs to evidence systematic patch prioritisation. In practice, a vulnerability that a national CERT has publicly flagged as under active exploitation, and left unpatched past its remediation deadline, is difficult to defend as an acceptable risk in an audit, an insurance review, or an internal risk assessment.
That framing matters more than the specific CVEs. The five additions are notable less for their individual severity than for their breadth: an MVC framework, a DNS resolver, an FTP server, a document server, and a CMS API. Each is the sort of infrastructure component that falls between the cracks when a vulnerability-management programme is scoped around SaaS and cloud-native assets.
Verification note
Technical specifics for each of the five entries — affected version ranges and per-CVE deadlines — should be confirmed against the KEV catalog itself before being cited in audit documentation. Where this article does not state a specific mechanism or version, that is deliberate: KEV entries are updated as CISA revises its assessments, and the catalog remains the authoritative source.
For teams maintaining patch-management evidence for internal or external review, the practical takeaway is straightforward: export the current KEV list, diff it against your asset inventory — including the DNS and FTP services that rarely make it there — and document the remediation deadlines CISA has published for each entry.
美國網絡安全和基礎設施安全局(CISA)已將五個漏洞加入其「已知被利用漏洞」(KEV)目錄,涉及 Apache Struts、ISC BIND、ProFTPD、ONLYOFFICE Docs 及 Strapi — 這組組成部分將迫使不少香港 IT 團隊把目光投向平常修補清單以外的範圍。
Security Affairs 於 4 月 22 日報道了是次新增。各漏洞的修補限期載於官方的 CISA KEV 目錄,各團隊應直接查閱該目錄,而非依賴二手報道。
香港 IT 團隊現階段應採取的行動
1. 優先審視 Apache Struts 及 ProFTPD。 Struts 的修補優先級最高。其歷史紀錄 — 尤其是 2017 年 Equifax 資料外洩事件,以及互聯網暴露漏洞在披露後數天內即被武器化攻擊的長久紀錄 — 意味着任何落後於 KEV 標示補丁的 Struts 實例,都應視為事故處理,而非積壓待辦項目。傳統 FTP 是另一個第一優先項目:ProFTPD 部署往往採用自行託管、監察鬆散,而且對以網絡應用程式及雲端負載為核心建立的漏洞管理計劃而言形同隱形。
2. 提醒 BIND 及 DNS 管理員。 BIND 漏洞被列入 KEV,意味着域名系統本身亦在監管範圍之內。如果貴機構的 DNS 由內部團隊或採用 ISC 軟件的託管服務商營運,應即時向 DNS 團隊開立專項工單 — 這類服務極少會出現在驅動修補周期的資產登記冊上,而 BIND 漏洞所帶來的可用性風險遠超機密性風險。
3. 檢查 ONLYOFFICE Docs 及 Strapi。 文件協作平台及 headless CMS 平台均部署於用戶存取範圍廣泛的內部網絡之上,而且兩者通常以 container 方式部署,其映像檔更新往往會悄然落後於上游修復。
為甚麼 KEV 的影響遠超華盛頓
KEV 目錄雖是美國政府清單,卻已成為事實上的國際基準 — 任何需要證明已系統性地為漏洞排定修補優先次序的機構,都會自然以其為參考。在實踐上,若某個漏洞已被國家級 CERT 公開標示為正被積極利用,卻在修補限期過後仍未修補,在審計、保險評估或內部風險評估中都很難辯稱其屬可接受風險。
這個框架比具體的 CVE 更為重要。五個新增漏洞之所以值得注意,與其說在於個別嚴重性,不如說在其涵蓋範圍:一個 MVC 框架、一個 DNS resolver、一個 FTP 服務器、一個文件服務器及一個 CMS API。每一個都是那類當漏洞管理計劃僅以 SaaS 及雲端原生資產為劃界範圍時,便會被遺漏的基礎設施組件。
驗證須知
五個條目的技術細節 — 受影響的版本範圍及各 CVE 的修補限期 — 應在引用於審計文件之前,先對照 KEV 目錄本身加以確認。本文未有陳述特定攻擊機制或版本之處,均屬刻意為之:KEV 條目會隨 CISA 修訂評估而更新,該目錄始終為權威來源。
對於須為內部或外部審核維護修補管理記錄的團隊,實際的建議相當直接:匯出最新的 KEV 清單,與貴機構的資產清單作出比對 — 包括那些極少被列入其中的 DNS 及 FTP 服務 — 並為 CISA 就各條目公布的修補限期留存文件紀錄。
