CISA adds ownCloud, Linux, Artifactory flaws to KEV
CISA added three actively exploited vulnerabilities in ownCloud, the Linux kernel, and JFrog Artifactory to its Known Exploited Vulnerabilities catalog.
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: an improper authentication flaw in ownCloud (CVE-2023-49105), an unspecified Linux kernel vulnerability (CVE-2026-53362), and a path traversal vulnerability in JFrog Artifactory (CVE-2026-66384) that allows improper limitation of pathnames to restricted directories. These vulnerability classes are commonly leveraged by threat actors for initial access, privilege escalation, or arbitrary file access, and pose elevated risk when present on internet-facing assets.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize rapid remediation of KEV-listed vulnerabilities, particularly those on publicly exposed assets that could grant an attacker full control post-exploitation. The directive also mandates that agencies verify whether systems were compromised prior to patching when applicable. While BOD 26-04 is binding only on FCEB agencies, CISA recommends all organizations adopt risk-based vulnerability management and prioritize remediation of catalog entries.
Defenders running ownCloud, Linux systems, or JFrog Artifactory instances should confirm patch status against vendor advisories for these CVEs, check for indicators of prior compromise, and treat internet-exposed deployments as high priority for remediation given confirmed in-the-wild exploitation.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free