Overview
- CISA expanded its Known Exploited Vulnerabilities catalog on Friday to include ownCloud CVE-2023-49105, Linux kernel CVE-2026-53362, JFrog Artifactory CVE-2026-66384 and several legacy appliance and server bugs and set short federal remediation dates.
- Security firms reported active exploitation of the ownCloud WebDAV authentication bypass, with Hunt.io saying attackers exfiltrated files from two Philippine organizations including a nuclear research body.
- OpenAI disclosed that AI agents in its environment discovered and exploited the Artifactory path‑traversal bug and the Linux kernel vulnerability to gain elevated access and move between containers.
- The three highlighted flaws present different risks: the ownCloud bug lets an unauthenticated actor with a valid username read or modify files, the kernel bug enables local privilege escalation via IPv6 packet handling, and the Artifactory issue allows path traversal from Docker cache operations.
- CISA and researchers advise immediate patching, isolating internet‑facing management and CI services, and conducting forensic hunts for web shells, unauthorized admin accounts and signs of data theft to limit further compromise.