Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Flags Critical OwnCloud, Linux Kernel, and JFrog Artifactory Flaws in KEV Catalog

CISA has listed three high‑severity vulnerabilities—ownCloud WebDAV (CVSS 9.8), Linux kernel IPv6 (CVSS 7.8), and JFrog Artifactory path‑traversal (CVSS 5.3)—as known exploited. Organizations must treat remediation as urgent and map the flaws to SOC 2 controls to maintain audit readiness.

LiveThreat™ Intelligence · 📅 August 29, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
1 recommended
📰
Source
securityaffairs.com

CISA Flags Critical OwnCloud, Linux Kernel, and JFrog Artifactory Flaws in KEV Catalog (CVE‑2023‑49105, CVE‑2026‑53362, CVE‑2026‑66384)

What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three high‑severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: an improper‑authentication issue in ownCloud WebDAV (CVSS 9.8), an out‑of‑bounds memory‑write bug in the Linux kernel IPv6 stack (CVSS 7.8), and a path‑traversal flaw in JFrog Artifactory’s Docker cache handling (CVSS 5.3).

Exploitability – All three have been observed in the wild. ownCloud’s flaw can be leveraged by an unauthenticated attacker who knows a username; the Linux kernel bug has been used by AI‑driven agents to gain root on worker nodes; the Artifactory issue allows an authenticated user to write outside the intended directory. CISA’s inclusion signals active exploitation.

Affected Products –

  • ownCloud Server 10.6.0‑10.13.0 (pre‑10.13.1) – WebDAV service
  • Linux kernel (IPv6 networking subsystem) – any distribution shipping the vulnerable kernel version
  • JFrog Artifactory – Docker cache handling component

Why It Matters for Compliance & Audit Readiness

  • Control Mapping & Continuous Evidence – Each flaw maps to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations). Demonstrating timely remediation and evidence collection satisfies audit expectations for “risk mitigation” and “change management.”
  • Audit‑Ready Documentation – CISA’s KEV listing provides an external, authoritative trigger for updating your risk register, patch‑management logs, and evidence repositories—critical for a defensible SOC 2 audit trail.
  • Enterprise Buyer Expectations – Prospective customers increasingly request proof that vendors monitor and remediate KEV‑listed vulnerabilities; a robust control‑mapping process becomes a competitive differentiator.

Recommended Actions

  • Map each CVE to the relevant SOC 2 controls (e.g., CC6.1, CC7.1) and record remediation status in your continuous compliance platform.
  • Apply vendor patches immediately – upgrade ownCloud to ≥ 10.13.1, update the Linux kernel to a patched release, and upgrade JFrog Artifactory to the latest version.
  • Validate remediation – run authenticated scans against WebDAV, IPv6 handling, and Artifactory cache paths; capture scan reports as audit evidence.
  • Update your risk register with CISA KEV references and set automated alerts for future KEV additions.

Source: Security Affairs – CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to KEV catalog

📰 Original Source
https://securityaffairs.com/198014/hacking/u-s-cisa-adds-owncloud-linux-kernel-and-jfrog-artifactory-flaws-to-its-known-exploited-vulnerabilities-catalog.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →