What Changed
CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation: CVE-2023-49105 in ownCloud, CVE-2026-53362 in the Linux kernel, and CVE-2026-66384 in JFrog Artifactory.
That matters because the three products sit in very different parts of enterprise environments. ownCloud can expose stored business data, Artifactory sits in software-delivery and package trust paths, and the Linux kernel can underpin far broader infrastructure than an application team may realize at first glance.
Why The KEV Label Matters More Than Another Vulnerability Roundup
Security teams rarely fail because they missed the headline. They fail because the affected technology is spread across different owners, asset maps are incomplete, and the normal change window was never designed for an actively exploited issue spanning collaboration platforms, infrastructure, and build systems at once.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Built from 100+ trusted cybersecurity sources.
Built from 100+ trusted cybersecurity sources.
CISA's BOD 26-04 framing is the useful part here. The agency is pushing federal teams to prioritize KEV issues on publicly exposed assets that can grant total control after exploitation and to check whether compromise happened before patching. Even outside government, that is the right mental model.
What To Verify First
- Map each CVE to real products, versions, and owners immediately: ownCloud deployments, Linux systems that match the vulnerable kernel path, and every Artifactory instance tied to internal or public package workflows.
- Check whether any affected systems are internet reachable, exposed through vendor or developer access, or tied to high-trust workflows such as file sharing, package publishing, CI/CD, remote administration, or business-critical services.
- If patching cannot happen immediately, decide which compensating controls, monitoring steps, or exposure reductions cover the gap and who is accountable for that decision.
- Review logs and administrative activity for evidence that exploitation may have already happened before patching, especially anywhere the affected systems bridge users, data stores, or software-delivery pipelines.
- Brief leadership and operational stakeholders early if the affected systems touch regulated, customer-facing, or continuity-sensitive processes.
Source Context
CyberExperts used CISA's KEV alert as the primary source for this article and preserved the details that change defender behavior: the specific CVEs, the affected technologies, the fact that active exploitation exists, and the expectation that teams check for compromise instead of treating patching as the whole job.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief