CISA Flags Critical OwnCloud, Linux Kernel, and JFrog Artifactory Flaws in KEV Catalog (CVE‑2023‑49105, CVE‑2026‑53362, CVE‑2026‑66384)
What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three high‑severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: an improper‑authentication issue in ownCloud WebDAV (CVSS 9.8), an out‑of‑bounds memory‑write bug in the Linux kernel IPv6 stack (CVSS 7.8), and a path‑traversal flaw in JFrog Artifactory’s Docker cache handling (CVSS 5.3).
Exploitability – All three have been observed in the wild. ownCloud’s flaw can be leveraged by an unauthenticated attacker who knows a username; the Linux kernel bug has been used by AI‑driven agents to gain root on worker nodes; the Artifactory issue allows an authenticated user to write outside the intended directory. CISA’s inclusion signals active exploitation.
Affected Products –
- ownCloud Server 10.6.0‑10.13.0 (pre‑10.13.1) – WebDAV service
- Linux kernel (IPv6 networking subsystem) – any distribution shipping the vulnerable kernel version
- JFrog Artifactory – Docker cache handling component
Why It Matters for Compliance & Audit Readiness
- Control Mapping & Continuous Evidence – Each flaw maps to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations). Demonstrating timely remediation and evidence collection satisfies audit expectations for “risk mitigation” and “change management.”
- Audit‑Ready Documentation – CISA’s KEV listing provides an external, authoritative trigger for updating your risk register, patch‑management logs, and evidence repositories—critical for a defensible SOC 2 audit trail.
- Enterprise Buyer Expectations – Prospective customers increasingly request proof that vendors monitor and remediate KEV‑listed vulnerabilities; a robust control‑mapping process becomes a competitive differentiator.
Recommended Actions
- Map each CVE to the relevant SOC 2 controls (e.g., CC6.1, CC7.1) and record remediation status in your continuous compliance platform.
- Apply vendor patches immediately – upgrade ownCloud to ≥ 10.13.1, update the Linux kernel to a patched release, and upgrade JFrog Artifactory to the latest version.
- Validate remediation – run authenticated scans against WebDAV, IPv6 handling, and Artifactory cache paths; capture scan reports as audit evidence.
- Update your risk register with CISA KEV references and set automated alerts for future KEV additions.
Source: Security Affairs – CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to KEV catalog