News

CISA adds ownCloud, Linux IPv6 and Artifactory to KEV

CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog on August 27: an ownCloud improper-authentication bug (CVE-2023-49105), a Linux kernel IPv6 local privilege-escalation bug (CVE-2026-53362), and a JFrog Artifactory path-traversal bug (CVE-2026-66384). The first two carry an August 30 federal deadline and a forensic-triage flag; Artifactory runs to September 10.

CISA adds ownCloud, Linux IPv6 and Artifactory to KEV

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on August 27, one in ownCloud, one in the Linux kernel, and one in JFrog Artifactory, per the agency's alert and the catalog itself. Read the entries for what they are. CISA names no threat actor and records ransomware use as unknown for all three. This is a separate batch from this week's earlier NetScaler and SQL Server additions.

Name each bug correctly

The two urgent ones share a federal remediation deadline of August 30, today for agencies under the directive, and CISA flags both for forensic triage.

  • CVE-2023-49105, an improper-authentication flaw in ownCloud Server, lets an unauthenticated attacker read, change or delete a user's files when the victim's username is known and no signing key is configured. This is a 2023 identifier resurfacing on the exploited list, not a fresh disclosure. ownCloud fixed it in Server 10.13.3, and the company's Infinite Scale product and its managed services are not affected.
  • CVE-2026-53362 is a local privilege-escalation bug in the Linux kernel's IPv6 networking path, not a remote unauthenticated RCE. An attacker already on the machine uses it to climb to higher privilege. CISA points to stable-tree kernel backports for the fix, so your exact patched build comes from your distribution's advisory, not from a single kernel commit hash.

The third runs on a later clock. CVE-2026-66384 is a path-traversal issue (CWE-22) in JFrog Artifactory: an authenticated user can write a file outside the intended Docker cache directory under specific remote-repository conditions. That is a constrained authenticated write, not remote code execution. JFrog rated it Medium in an advisory published August 12 and shipped fixes in 7.146.35 and 7.161.16. JFrog Cloud is already fortified, so the actionable exposure is self-hosted Artifactory, and its KEV deadline is September 10.

What CISA is and is not saying

CISA's alert carries its standard note that vulnerabilities like these "are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise." What it does not add is attribution. There is no named group, no confirmed ransomware link, and the ownCloud and kernel rows carry a forensic-triage flag while the Artifactory row does not. Some single-source victim claims are circulating around the ownCloud bug; they are not part of CISA's entry, so keep them in the separate-reporting column until a named party confirms.

The takeaway

If you run federal-adjacent infrastructure, work the two August 30 rows first: patch ownCloud Server to 10.13.3 or later and apply your distribution's kernel update for the IPv6 local-escalation bug, both today, and open forensic triage on any host that was reachable rather than assuming a clean patch closes the book. Self-hosted Artifactory can follow on the September 10 clock, moving to 7.146.35 or 7.161.16. When you brief your own team, do not reclassify the Artifactory write as an RCE or the kernel bug as remote. The deadline is real, the panic framing is not.

For related context, see our coverage of the Gitea flaw added to KEV, OpenAI's Hugging Face incident report, and the Claude Code Auto Mode prompt-injection finding.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free