CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerabilities are CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified), and CVE-2026-66384 (JFrog Artifactory Path Traversal). These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04 establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, requiring prioritization of remediation for high-risk vulnerabilities listed in the KEV Catalog. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
What we know
BOD 26-04 requires agencies to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation.
▤ 1 sources›
The vulnerability is an improper access control vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
▤ 1 sources›
Binding Operational Directive (BOD) 26-04 requires FCEB agencies to prioritize remediation of KEV Catalog vulnerabilities.
Binding Operational Directive (BOD) 26-04 applies to Federal Civilian Executive Branch (FCEB) agencies.
▤ 1 sources›
The vulnerabilities are CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, and CVE-2026-8452.
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) Catalog.
The vulnerabilities affect Red Hat, Microsoft, Ajax.NET, Linux, and Citrix products.
▤ 1 sources›
There is evidence of active exploitation.
CISA encourages all organizations to adopt risk-based vulnerability management.
▤ 1 sources›
CISA issued the advisory on August 25, 2026.
▤ 1 sources›
The vulnerability is a Gitea code injection vulnerability.
▤ 1 sources›
CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, including CVEs in ownCloud, Linux Kernel, and JFrog Artifactory.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.