CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerabilities are CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified), and CVE-2026-66384 (JFrog Artifactory Path Traversal). These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04 establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, requiring prioritization of remediation for high-risk vulnerabilities listed in the KEV Catalog. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
What we know
BOD 26-04 requires agencies to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation.
▤ 1 sources›
The vulnerability is an improper access control vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
▤ 1 sources›
Binding Operational Directive (BOD) 26-04 requires FCEB agencies to prioritize remediation of KEV Catalog vulnerabilities.
Binding Operational Directive (BOD) 26-04 applies to Federal Civilian Executive Branch (FCEB) agencies.
▤ 1 sources›
The vulnerabilities are CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, and CVE-2026-8452.
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) Catalog.
The vulnerabilities affect Red Hat, Microsoft, Ajax.NET, Linux, and Citrix products.
▤ 1 sources›
There is evidence of active exploitation.
CISA encourages all organizations to adopt risk-based vulnerability management.
▤ 1 sources›
CISA issued the advisory on August 25, 2026.
▤ 1 sources›
The vulnerability is a Gitea code injection vulnerability.
▤ 1 sources›
Open any source to inspect its original language, when DoseFix received it, and the claims it supports.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
cisa.gov · EN · Published · ReceivedCISA Adds Six Known Exploited Vulnerabilities to Catalog
cisa.gov · EN · Published · ReceivedCISA Adds One Known Exploited Vulnerability to Catalog
cisa.gov · EN · Published · ReceivedCISA Adds One Known Exploited Vulnerability to Catalog
cisa.gov · EN · Published · ReceivedLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.