← All guides
Guide

CISA Flags Three Actively Exploited Vulnerabilities—Including ownCloud and Linux Kernel Flaws

CISA added three actively exploited CVEs to its KEV catalog, including ownCloud auth bypass and Linux kernel flaws. If you run these systems, patching isn't optional—attackers are already using them.

What Happened

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed active exploitation in the wild. The additions include an ownCloud authentication bypass (CVE-2023-49105), an unspecified Linux kernel vulnerability (CVE-2026-53362), and a path traversal flaw in JFrog Artifactory (CVE-2026-66384). Federal agencies are now required under Binding Operational Directive 26-04 to prioritize remediation of these high-risk vulnerabilities on publicly exposed assets that could grant attackers total control post-exploitation.

Why SMBs Should Care

While CISA's directive targets federal agencies, the KEV catalog is a critical early warning system for all organizations. These aren't theoretical risks—threat actors are actively exploiting these flaws right now. For SMBs running ownCloud for file sharing, Linux-based infrastructure, or JFrog Artifactory for development pipelines, these vulnerabilities represent immediate attack vectors for ransomware deployment, data theft, and lateral movement. Many SMBs lack the monitoring to detect exploitation attempts, making rapid patching essential. If your team uses any of these platforms, prioritize patching immediately and review your exposure on internet-facing systems.

Read the full CISA alert

Need help assessing your vulnerability posture or accelerating patch management? O-Cyrus helps SMBs prioritize security updates based on real-world risk and maintain resilient infrastructure. Contact our security team or learn more at o-cyrus.com.

Related services

Need a hand with this?

O-Cyrus helps small businesses with websites, DNS, custom apps, and the everyday tech that keeps things running.

Talk to us →