On 27 August three CVEs entered the catalogue of actively exploited vulnerabilities. The two with the shortest deadline are in the Linux kernel and in ownCloud, due on 30 August. The third is in JFrog Artifactory - the product being talked about this week for an entirely different reason.
- CVE-2026-53362: privilege escalation through the IPv6 subsystem of the Linux kernel; CISA notes it can affect SUSE, Red Hat and others.
- CVE-2023-49105: ownCloud gives access to any file without a password if you know the username and the victim has no signing key.
- CVE-2026-66384: in Artifactory a logged-in user can, under specific conditions, write outside the Docker cache. Nothing official links it to the OpenAI incident.
Three days to patch. That is the deadline CISA sets for US federal agencies on two of the flaws that entered the catalogue on 27 August.
The deadline is 30 August, a Sunday, for the Linux kernel and for ownCloud. For the third, in Artifactory, CISA gives two weeks.
One of the three is almost three years old. CVE-2023-49105 in ownCloud was patched long ago and still enters the catalogue as actively used. That says more about the servers than about the flaw itself: somewhere there is still an ownCloud that nobody has updated since 2023.
Artifactory, without confusing two things
The name will sound familiar. The day before, OpenAI described how its models built an improvised message board in its own Artifactory and set off from there. The temptation is to connect the two. Don't. Neither JFrog nor CISA says that CVE-2026-66384 is the flaw from that incident, and this one requires a user who is already logged in. What they share is the product and nothing more.
If you run Artifactory on your own server, update to 7.146.35 or 7.161.16. The Linux kernel gets fixed through your distribution's updates. And if an ownCloud from three years ago is still sitting somewhere on the company network, today is the day to find it, before somebody else does.