TL;DR
On August 27, 2026, CISA added three active threats to the KEV Catalog. These critical flaws impact ownCloud, the Linux Kernel, and JFrog Artifactory installations globally. Successful exploitation of these vulnerabilities can allow an attacker to fully compromise device integrity.
- Product: n/a, Linux +1
- Vulnerabilities: 3 flaws (CVE-2023-49105, CVE-2026-53362, CVE-2026-66384)
- Highest severity: 9.8 (Critical · CVSSv3)
- Status: 3 exploited; patches available
- Action: Update to 14200d435af9a9eeb444f529fc2f689a236b7962, 65fb14cbebb0cd0eff903a22d33537ddc8b95769, 46f201f8b4c39633a1fa3dc12459f506d470993d, 6374fb9edf72c67a118a2c214a0dddd04c921e0a (+10) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2023-49105 | 9.8 | CWE-287 | — | Exploited |
| CVE-2026-53362 | 7.8 | CWE-787 | 14200d435af9a9eeb444f529fc2f689a236b7962, 65fb14cbebb0cd0eff903a22d33537ddc8b95769, 46f201f8b4c39633a1fa3dc12459f506d470993d (+9) | Exploited |
| CVE-2026-66384 | 5.3 | CWE-22 | 7.146.35, 7.161.16 | Exploited |
Why the Vulnerabilities Matter
The CISA KEV Catalog serves as a definitive priority list for network defenders. Officials confirmed active exploitation in the wild for all three flaws. Delaying remediation exposes organizations to severe threats. These risks include privilege escalation, system crashes, and data corruption. CISA has not published specific counts of affected users. However, these systems represent frequent attack vectors for malicious cyber actors.
How the Attacks Work
These vulnerabilities exploit distinct mechanisms across different platforms. First, in ownCloud, attackers exploit CVE-2023-49105 using pre-signed URLs. The application accepts these URLs even without a configured signing key. This gap grants unauthorized users direct file access. Second, for CVE-2026-53362, the Linux kernel IPv6 subsystem miscalculates parameter lengths. Attackers use crafted UDP sockets to trigger a kernel memory overwrite. Third, regarding CVE-2026-66384, JFrog Artifactory suffers from improper pathname limitations. This defect allows authenticated users to write data far outside the restricted Docker cache path.
Affected Versions
The ownCloud vulnerability impacts core versions from 10.6.0 up to 10.13.0. Meanwhile, the Linux kernel flaw affects unpatched IPv6 networking subsystems across various distributions. Finally, the JFrog Artifactory flaw impacts unpatched deployments handling specific remote-repository conditions.
Patch and Mitigation Steps
System administrators must apply the latest vendor patches immediately. Federal agencies face strict deadlines to secure their infrastructure. Organizations should routinely monitor the CISA KEV Catalog to maintain a hardened security posture against emerging network threats.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!