The Cybersecurity and Infrastructure Security Agency added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, 2026, citing evidence of active exploitation. The additions are CVE-2023-49105, an improper authentication vulnerability in ownCloud; CVE-2026-53362, an unspecified vulnerability in the Linux Kernel; and CVE-2026-66384, an improper limitation of a pathname to a restricted directory vulnerability affecting JFrog Artifactory, according to CISA’s alert.
CISA’s advisory notes that vulnerabilities of this type are “a frequent attack vector for malicious cyber actors” and pose significant risk to federal networks. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies are required to remediate KEV catalog entries within CISA-specified timeframes, though the directive does not legally bind private-sector organizations.
The JFrog Artifactory path traversal flaw is notable given the platform’s widespread use as a binary and package repository in enterprise software development pipelines; a pathname restriction bypass in that context can potentially allow an attacker to read or write files outside intended directories, a class of vulnerability that has previously been leveraged for both data exfiltration and remote code execution in build and artifact-management systems. The ownCloud authentication flaw, tracked since 2023, affects a self-hosted file-sharing platform used by organizations that manage sensitive document storage internally rather than through commercial cloud providers.
CISA said it “will continue to add vulnerabilities to the catalog that meet the specified criteria” and encouraged all organizations, not just federal agencies, “to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.” The agency’s KEV catalog has become a widely used reference point across the security industry for prioritizing patch management amid a growing volume of disclosed vulnerabilities.

Leave a Reply