ON August 28, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities catalog, specifically: 1. CVE-2023-49105 (ownCloud Improper Authentication - CVSS score 9.8) allows unauthenticated access to user files; 2. CVE-2026-53362 (Linux Kernel Out-of-Bounds Memory Write - CVSS score 7.8) could let attackers overwrite kernel memory, leading to crashes or privilege escalation; 3.
CVE-2026-66384 (JFrog Artifactory Path Traversal - CVSS score 5.3) enables authenticated users to manipulate file paths. CISA mandates federal agencies to remediate these vulnerabilities promptly to protect their networks.