← All briefings

ownCloud · Linux Kernel · JFrog Artifactory

Date: 2026-08-28 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

CISA added three actively exploited vulnerabilities to its KEV Catalog: ownCloud authentication bypass, Linux Kernel privilege escalation, and JFrog Artifactory path traversal. All have near-term remediation deadlines, with ownCloud and Linux Kernel due by 2026-08-30. German reporting also indicates active exploitation of an unassigned PaperCut NG/MF vulnerability and newly published exploit code for an Exchange vulnerability; CVE identifiers and technical details were not provided in the collected data.

Critical Vulnerabilities

CVE-2023-49105 — ownCloud

  • Severity: Not provided in the collected data
  • EPSS: Not provided
  • Technical detail: An improper authentication vulnerability allows an unauthenticated attacker to access, modify, or delete files when the victim’s username is known and no signing key is configured. The issue affects ownCloud deployments where the relevant signing-key protection has not been enabled, creating a direct confidentiality and integrity risk for internet-facing file-sharing services.
  • Exploitation status: Actively exploited; added to the CISA KEV Catalog on 2026-08-27.
  • Remediation: Apply the current ownCloud security updates and configure signing keys as recommended by the vendor. Identify internet-exposed instances, review access and download logs for anomalous activity, and validate file integrity. CISA remediation deadline: 2026-08-30.

CVE-2026-53362 — Linux Kernel

  • Severity: Not provided in the collected data
  • EPSS: Not provided
  • Technical detail: The vulnerability affects the IPv6 networking subsystem and may permit local privilege escalation. It can affect multiple Linux distributions, including SUSE and Red Hat-derived systems, as well as products incorporating the Linux Kernel. Exploitation would be particularly significant on multi-user servers, container hosts, and systems where an attacker has already obtained a low-privileged foothold.
  • Exploitation status: Actively exploited; added to CISA KEV on 2026-08-27.
  • Remediation: Install the latest kernel updates supplied by the relevant distribution and reboot systems where required. Prioritize internet-facing servers, container infrastructure, and shared environments. CISA remediation deadline: 2026-08-30. Treat exploitation evidence as a trigger for host-level forensic review.

CVE-2026-66384 — JFrog Artifactory

  • Severity: Not provided in the collected data
  • EPSS: Not provided
  • Technical detail: An authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions. The path traversal weakness can affect software supply-chain infrastructure by enabling repository manipulation, unauthorized file placement, or abuse of build and artifact workflows. Exploitation requires authenticated access and particular Artifactory repository configuration.
  • Exploitation status: Actively exploited; added to CISA KEV on 2026-08-27.
  • Remediation: Apply the current JFrog Artifactory security release, review remote-repository and Docker-cache configurations, and audit repository contents and administrative activity. Rotate credentials if unauthorized artifact or configuration changes are identified. CISA remediation deadline: 2026-09-10.

CVE-2026-74820 / CVE-2026-18886 / CVE-2026-18885 — ServiceNow AI Platform

  • Severity: CVSS 10.0 for each vulnerability
  • EPSS: 0.0 in the collected EUVD data; this does not indicate absence of future exploitation.
  • Technical detail: ServiceNow remediated three vulnerabilities in its AI Platform involving SQL injection, improper access control, and code injection. The descriptions indicate that unauthenticated exploitation may be possible in certain circumstances, potentially enabling unauthorized data access or arbitrary code execution. Affected releases span multiple ServiceNow product families and patch branches.
  • Exploitation status: No confirmed exploitation reported.
  • Remediation: Apply the applicable ServiceNow hotfix or patch level for each deployment branch. Confirm versions against the vendor’s advisory rather than relying only on the CVE list, and review externally reachable AI Platform interfaces and logs for suspicious unauthenticated requests.

ONGOING:

  • CVE-2026-8452 (Citrix NetScaler ADC/Gateway): Actively exploited; patch before the 2026-08-29 deadline and restrict management interfaces.
  • CVE-2026-63520 (Microsoft SharePoint): Active exploitation and public PoC remain reported; patch on-premises instances and hunt for web shells.
  • CVE-2026-60004 (Gitea): KEV deadline is today; patch to at least 1.27.1 and audit Git hook directories.
  • CVE-2019-1068 (Microsoft SQL Server): Actively exploited; patch before 2026-08-30 and review authenticated database connections.
  • CVE-2022-0995 (Linux Kernel): KEV-listed local privilege escalation; apply distribution kernel updates.
  • CVE-2026-19478 (GitLab): Actively exploited; upgrade to the fixed release versions.

European Advisories

  • WID-SEC-2026-1686 (Samba, UPDATE): BSI rates multiple Samba vulnerabilities critical, including possible code execution, file manipulation, security bypass, and denial of service. Apply current Samba updates and review externally accessible SMB services.
  • WID-SEC-2026-1190 (GNU libc, UPDATE): Critical vulnerabilities may permit remote anonymous attacks, file manipulation, or denial of service. Apply distribution updates.
  • WID-SEC-2026-2640 (Linux Kernel, UPDATE): BSI reports critical kernel issues affecting confidentiality, integrity, availability, and privilege boundaries. The KEV-listed Linux issue is covered in Critical Vulnerabilities.
  • WID-SEC-2026-2147 (Citrix NetScaler, UPDATE): Covered in Critical Vulnerabilities; patch actively exploited appliances immediately.
  • WID-SEC-2026-3055 (OpenCTI, NEW): Multiple vulnerabilities may enable security-control bypass, information disclosure, data manipulation, or denial of service. Patch OpenCTI deployments and restrict administrative access.
  • WID-SEC-2026-3046 (IBM Concert, NEW): BSI reports vulnerabilities including RCE, SQL injection, XSS, data manipulation, and security bypass. Apply IBM fixes and assess exposure of management interfaces.
  • WID-SEC-2026-3043 (IBM QRadar SIEM, NEW): Issues may enable privilege escalation, security bypass, information disclosure, and code execution. Prioritize patching because QRadar is security-critical infrastructure.

Active Threats and Campaigns

  • PaperCut NG/MF zero-day exploitation — STATUS CHANGE: PaperCut reportedly warned that attackers are exploiting a vulnerability across all versions of NG and MF. The collected reporting does not provide a CVE, fixed version, or confirmed attack indicators. Identify exposed PaperCut servers, restrict administrative access, obtain vendor guidance, and review web, application, and authentication logs for unauthorized activity. Bleeping Computer
  • Internet-exposed edge systems — ONGOING: The UK NCSC highlighted disruptive activity and the continued risk posed by internet-exposed systems and edge devices. Maintain external attack-surface monitoring and prioritize rapid remediation of edge appliances.
  • Microsoft 365 phishing campaigns — ONGOING: NovaCookies and Mirage2FA remain relevant for session-token theft and MFA bypass. Hunt for anomalous OAuth activity, unfamiliar session origins, and conditional-access exceptions.

Security News and Context

  • A cyberattack against Berlin’s administration reportedly enabled data exfiltration over several days; the initial intrusion point remains unclear. Review privileged access, identity-provider, and egress telemetry for comparable patterns. Heise Security
  • Australian authorities arrested and charged two alleged TeamPCP members linked to major software supply-chain attacks. The development reinforces the need to validate third-party packages, scanners, and build dependencies. Heise Security
  • CISA and UK NCSC reporting continues to emphasize shrinking exploitation windows for internet-facing systems and edge devices.
  1. Patch ownCloud and affected Linux Kernel systems before the 2026-08-30 KEV deadline.
  2. Patch JFrog Artifactory and audit Docker caches, remote repositories, and artifact integrity.
  3. Identify and isolate all PaperCut NG/MF instances; monitor for exploitation while awaiting vendor-specific details.
  4. Patch ServiceNow AI Platform and Now Platform branches against the listed critical CVEs.
  5. Complete Citrix NetScaler remediation before 2026-08-29 and verify no exposed management interfaces.
  6. Patch Gitea immediately; its KEV deadline is today.
  7. Continue remediation of previously reported items: CVE-2026-63520, CVE-2019-1068, CVE-2026-19478, CVE-2026-73570, CVE-2026-64849, and CVE-2026-68820.