CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog
CISA has added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), and CVE-2026-66384 (JFrog Artifactory) to its Known Exploited Vulnerabilities Catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion signifies that these flaws have been observed under active exploitation in the wild, posing a significant threat to organizations.
The newly cataloged vulnerabilities include CVE-2023-49105, an improper authentication vulnerability affecting ownCloud instances. This flaw could allow unauthorized users to gain access to sensitive data or system functionalities. Additionally, CVE-2026-53362, an unspecified vulnerability within the Linux Kernel, has been added, highlighting potential risks to the core operating system. The third addition is CVE-2026-66384, a vulnerability in JFrog Artifactory related to improper limitation of a pathname to a restricted directory, which could lead to directory traversal attacks.
These vulnerabilities are considered high-risk due to their active exploitation. CISA's Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of such high-risk vulnerabilities, particularly those present on public-facing assets that could grant complete control of the asset upon exploitation. This directive underscores the urgency for federal agencies to address these specific flaws.
The KEV Catalog serves as a critical resource for organizations to identify and prioritize the patching of vulnerabilities that are actively being targeted by malicious actors. By focusing remediation efforts on these known exploited flaws, agencies can significantly reduce their attack surface and mitigate the risk of successful cyber intrusions.
While BOD 26-04 specifically applies to FCEB agencies, CISA strongly encourages all organizations, regardless of sector, to adopt a risk-based vulnerability management approach. Prioritizing the patching of vulnerabilities listed in the KEV Catalog is a key component of this strategy, helping to defend against prevalent threats.
CISA continues to monitor the threat landscape and will add further vulnerabilities to the KEV Catalog as evidence of active exploitation emerges. The agency also provides a nomination form for the public to submit vulnerabilities that they believe warrant inclusion in the catalog, provided they have a CVE ID, evidence of exploitation, and clear mitigation guidance.
The inclusion of these three vulnerabilities serves as a stark reminder of the dynamic nature of cyber threats and the ongoing need for vigilant security practices. Organizations are urged to review their systems for these specific CVEs and implement necessary patches and mitigations promptly to protect against potential compromise.