CISA Adds Three Known Exploited Vulnerabilities to the KEV Catalog
Summary
On 27 August 2026 CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation in the wild. The three entries cover a cross-section of technology commonly used across government, enterprise and academia.
The three vulnerabilities
- CVE-2023-49105 โ affects ownCloud, an improper authentication issue (authentication bypass). This is considered the most notable of the batch because it mirrors an earlier ownCloud attack pattern and should be patched promptly on any internet-exposed ownCloud instance.
- CVE-2026-53362 โ affects the Linux Kernel; technical detail unspecified at the time of addition.
- CVE-2026-66384 โ affects JFrog Artifactory, an improperly limited flaw.
Significance
Inclusion in the KEV Catalog is a formal CISA determination that a vulnerability is being actively exploited in the wild. Under the Binding Operational Directive (BOD) timelines, US federal agencies must remediate these vulnerabilities and check for pre-patch compromise. For the wider community, the KEV Catalog is effectively the highest-priority patch list that defenders can treat as confirmed real-world risk, and it is often adopted beyond the federal government as the default quick call for patching priorities.
AU/NZ relevance
The ownCloud addition is especially relevant to Australia and NZ because ownCloud is run by many Australian and New Zealand agencies and universities as an internet-exposed file-sharing platform. Australian and New Zealand teams should treat the three additions as immediate remediation items against their own asset maps, and align with the CISA timelines that underpin the KEV Catalog.