ownCloud, JFrog Artifactory and Linux Kernel Flaws Added to CISA’s Exploited Catalog

Category: CISA Advisories

Have you ever locked the front door of your business but forgotten that a side window was still open?

That is what many software vulnerabilities create. The main security controls may be working, but one overlooked flaw can still give an attacker a way inside.

On August 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. The affected products include ownCloud, the Linux kernel, and JFrog Artifactory.

KEV listings matter because they indicate that vulnerabilities are being exploited in real-world attacks, not merely discussed as theoretical risks.

Here is what you need to know.

CISA KEV advisory at a glance

CVE Affected product Severity Primary impact CISA due date
CVE-2023-49105 ownCloud Server core before 10.13.1 CVSS 9.8 Critical Unauthenticated access, modification, or deletion of files August 30, 2026
CVE-2026-53362 Linux kernel IPv6 networking subsystem CVSS 7.8 High Local privilege escalation August 30, 2026
CVE-2026-66384 JFrog Artifactory CVSS 5.3 Medium Authenticated file writes outside the intended Docker cache path September 10, 2026

The first two deadlines are especially urgent. If you operate one of these systems, do not wait for your normal monthly maintenance cycle.

CVE-2023-49105: ownCloud authentication bypass

Laptop with an abstract lock, physical key, and secure data storage case representing cloud authentication

Imagine giving someone a temporary key to one file cabinet. The key is supposed to work only when it has been properly signed and verified.

Now imagine the lock accepting that key even though no signing key exists.

That is the basic problem behind CVE-2023-49105. A pre-signed URL: a link intended to provide controlled, temporary access to a file: could be accepted by vulnerable ownCloud Server installations even when no signing key was configured for the file owner.

According to the NVD record, an attacker who knows a victim’s username could access, modify, or delete any of that user’s files without authentication.

The earliest affected version is 10.6.0, and the vulnerability affects ownCloud core versions before 10.13.1. The CVSS score is 9.8 Critical, reflecting remote access, low complexity, no required privileges, and the potential loss of confidentiality, integrity, and availability.

And here is where it gets scary: your employees do not need to click a malicious link for this flaw to matter. If the ownCloud server is exposed and usernames can be identified, the attacker may be able to target business files directly.

What to do about CVE-2023-49105

Start by identifying every self-hosted ownCloud Server instance in your environment.

Then:

  • Upgrade ownCloud core to 10.13.1 or later.
  • Prefer ownCloud’s more recent recommended baseline of 10.13.3 where possible.
  • Review the vendor’s ownCloud security guidance.
  • If an upgrade is not immediately possible, ask ownCloud Support about the specific patch for this issue.
  • Review WebDAV logs for unusual unauthenticated file access, downloads, modifications, or deletions.
  • Check whether sensitive files were changed or removed.
  • Restrict external access to the ownCloud service until remediation is complete, if business operations allow it.

CISA marks this vulnerability as requiring forensic triage under BOD 26-04. That means patching alone may not be enough. You should also investigate whether an attacker accessed or changed files before the update.

CVE-2026-53362: Linux kernel IPv6 privilege escalation

Technician securing a network cable on a compact server appliance with blue network visualizations in the background

The second vulnerability is in the Linux kernel’s IPv6 networking subsystem.

Think of the kernel as the building manager for a Linux system. It controls memory, networking, processes, and access to critical resources. If a local user can trick that manager into mishandling memory, the user may gain authority far beyond what their account should have.

CVE-2026-53362 involves an out-of-bounds write in the UDPv6 path. In plain language, the kernel can write data beyond the memory space it properly allocated.

An unprivileged local user can trigger the issue through a UDPv6 socket using the MSG_MORE and MSG_SPLICE_PAGES mechanisms. The result can include memory corruption and privilege escalation: the ability to move from a limited account to highly privileged control of the Linux host.

The vulnerability can affect multiple Linux products and distributions, including systems based on SUSE and Red Hat. The NVD record identifies a CVSS score of 7.8 High.

CISA lists forensic triage as required for this CVE, with a remediation deadline of August 30, 2026.

What to do about CVE-2026-53362

Do not assume that “Linux” tells you whether a system is affected. The kernel version and distribution backports matter.

Take these steps:

  • Inventory Linux servers, appliances, virtual machines, and cloud workloads.
  • Check kernel versions against updates from Red Hat, SUSE, and your distribution vendor.
  • Install the vendor-provided kernel update that addresses CVE-2026-53362.
  • Reboot systems when required so the patched kernel is actually running.
  • Review authentication, process, and system logs for suspicious local activity.
  • Investigate unexpected crashes, privilege changes, or unusual IPv6 and UDP behavior.
  • If patching must be delayed, limit untrusted local access and review whether IPv6 can be restricted temporarily.

The upstream correction is associated with the kernel fix titled “ipv6: account for fraggap on the paged allocation path.” You can review the kernel patch through kernel.org.

CVE-2026-66384: JFrog Artifactory Docker cache path traversal

Software engineer reviewing a secure container deployment beside bounded translucent software blocks in a bright office

The third issue affects JFrog Artifactory.

Picture a warehouse with a clearly marked storage area. A worker has permission to place boxes in one section, but a flaw in the warehouse routing system lets that worker place a box outside the approved boundary.

CVE-2026-66384 is similar. Under specific remote-repository conditions, an authenticated Artifactory user may write data outside the intended Docker cache path.

This is classified as CWE-22, or improper limitation of a pathname to a restricted directory. The CVSS score is 5.3 Medium, but the KEV listing makes the risk more urgent because CISA has identified the vulnerability as exploited.

Affected versions include:

  • Artifactory versions before 7.146.35
  • Artifactory versions 7.161.0 through 7.161.15

The fixed versions are 7.146.35 and 7.161.16, respectively. JFrog’s security advisory states that cloud environments have been fortified, while self-hosted customers must upgrade.

What to do about CVE-2026-66384

If you manage Artifactory yourself:

  • Confirm your exact Artifactory version.
  • Upgrade to the fixed release for your branch.
  • Review Docker remote-repository and cache configurations.
  • Restrict repository and cache permissions to only users who need them.
  • Review logs for unexpected writes or unusual path values.
  • Investigate activity from authenticated users who do not normally manage Docker repositories.
  • Verify the integrity of cached images and related deployment files.

CISA lists the remediation deadline as September 10, 2026. That gives you more time than the ownCloud and Linux deadlines, but the issue still deserves prompt action.

For this CVE, CISA marks forensic triage as not required under BOD 26-04. You should still investigate suspicious activity if your logs show unusual file writes.

What BOD 26-04 means for your business

BOD 26-04, titled Prioritizing Security Updates Based on Risk, directs federal agencies to prioritize vulnerabilities based on factors such as active exploitation, exposure, impact, and available mitigations.

Your small business may not be directly bound by the directive. Still, the framework is useful.

Here is the practical takeaway:

  • Patch vulnerabilities known to be exploited first.
  • Prioritize internet-facing systems.
  • Treat critical data stores as urgent.
  • Preserve and review evidence when CISA requires forensic triage.
  • Document what you found, what you patched, and when you verified the fix.

That is a sensible approach whether your business is in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, or anywhere else in Missouri.

How Platinum Web Services can help

You should not have to guess whether an old kernel, cloud file server, or software repository is putting your business at risk.

Platinum Web Services provides managed IT services, cybersecurity solutions, cloud services, network design, data recovery, and 24/7 emergency support for small businesses.

We help organizations with:

  • Vulnerability and patch management
  • Linux and server updates
  • Cloud security reviews
  • Log and forensic triage
  • Backup and data recovery planning
  • Network security and access controls
  • Ongoing security monitoring

Whether you need St. Louis cybersecurity solutions, St. Charles County managed IT services, Chesterfield cloud services, Clayton cyber security solutions, O’Fallon network design and 24/7 support, or Metro East data recovery and laptop/desktop repairs, our team can help you build a more secure technology foundation.

The best time to find an unpatched door is before someone walks through it. If you would like help reviewing these CISA advisories, contact Platinum Web Services.

Sources

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *