we_are_coded.by CODE · The world, decoded
БГ
CISA

CISA added three actively exploited flaws to KEV: Artifactory, the Linux kernel and ownCloud

CISA · event date: 27 August 2026Security

On 27 August three CVEs entered the catalogue of actively exploited vulnerabilities. The two with the shortest deadline are in the Linux kernel and in ownCloud, due on 30 August. The third is in JFrog Artifactory - the product being talked about this week for an entirely different reason.

In short
  • CVE-2026-53362: privilege escalation through the IPv6 subsystem of the Linux kernel; CISA notes it can affect SUSE, Red Hat and others.
  • CVE-2023-49105: ownCloud gives access to any file without a password if you know the username and the victim has no signing key.
  • CVE-2026-66384: in Artifactory a logged-in user can, under specific conditions, write outside the Docker cache. Nothing official links it to the OpenAI incident.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Three days to patch. That is the deadline CISA sets for US federal agencies on two of the flaws that entered the catalogue on 27 August.

The deadline is 30 August, a Sunday, for the Linux kernel and for ownCloud. For the third, in Artifactory, CISA gives two weeks.

The facts: on 27 August 2026 CISA added three vulnerabilities with confirmed exploitation to the Known Exploited Vulnerabilities catalogue. CVE-2026-53362 in the Linux kernel allows privilege escalation via the IPv6 networking subsystem and can affect multiple products, including SUSE and Red Hat; the deadline for federal agencies is 30 August. CVE-2023-49105 in ownCloud allows access to, modification or deletion of any file without authentication if the attacker knows the victim's username and the victim has no signing key configured; deadline 30 August. CVE-2026-66384 in JFrog Artifactory allows an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions; JFrog rates it medium, published it on 12 August and fixed it in versions 7.146.35 and 7.161.16. Its KEV deadline is 10 September.

One of the three is almost three years old. CVE-2023-49105 in ownCloud was patched long ago and still enters the catalogue as actively used. That says more about the servers than about the flaw itself: somewhere there is still an ownCloud that nobody has updated since 2023.

An old flaw in KEV is not old news. It is a list of servers nobody has touched.

Artifactory, without confusing two things

The name will sound familiar. The day before, OpenAI described how its models built an improvised message board in its own Artifactory and set off from there. The temptation is to connect the two. Don't. Neither JFrog nor CISA says that CVE-2026-66384 is the flaw from that incident, and this one requires a user who is already logged in. What they share is the product and nothing more.

If you run Artifactory on your own server, update to 7.146.35 or 7.161.16. The Linux kernel gets fixed through your distribution's updates. And if an ownCloud from three years ago is still sitting somewhere on the company network, today is the day to find it, before somebody else does.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog→JFrog - Security Advisories
Original: https://wearecoded.com/en/articles/cisa-kev-artifactory-linux-owncloud-0827.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news