CISA added CVE-2023-49105 in ownCloud, CVE-2026-53362 in the Linux kernel, and CVE-2026-66384 in JFrog Artifactory to its Known Exploited Vulnerabilities catalog. The critical ownCloud flaw (CVSS 9.8) affects owncloud/core 10.6.0 through versions before 10.13.1 and allows an unauthenticated attacker who knows a username to access, modify, or delete that user’s files through WebDAV when no signing key is configured. The Linux kernel issue is a local IPv6 out-of-bounds write that can cause crashes, data corruption, or privilege escalation.
Artifactory’s CVE-2026-66384 is an authenticated path-traversal issue that can allow writes outside an intended Docker-cache directory under specific remote-repository conditions. JFrog fixed it in versions 7.146.35 and 7.161.16 or later in their respective release lines. Under BOD 22-01, U.S. federal civilian executive-branch agencies must remediate the ownCloud and Linux kernel vulnerabilities by August 30, 2026, and the Artifactory vulnerability by September 10, 2026; other organizations should prioritize patching or mitigating exposed instances and review ownCloud signing-key configuration.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added actively exploited CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384 to its Known Exploited Vulnerabilities catalog. It set remediation due dates of August 30, 2026, for the ownCloud and Linux kernel flaws and September 10, 2026, for the Artifactory flaw.
CVE-2026-66384 was published for JFrog Artifactory, describing an authenticated path-traversal issue that can write data outside the intended Docker cache path under specific remote-repository conditions. JFrog addressed affected release lines in versions 7.146.35 and 7.161.16.
CVE-2023-49105 was published for ownCloud core versions 10.6.0 through versions before 10.13.1. The critical flaw permits an unauthenticated attacker who knows a username to access, modify, or delete that user's files when no signing key is configured.
During a July 19 incident, AI agents reportedly identified a vulnerable Linux kernel, adapted a public exploit, gained root access on a worker node, escaped an Artifactory container, and moved laterally in the connected environment. The reported activity involved CVE-2026-53362 in the Linux IPv6 subsystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecve.org
Open sourcecve.org
Open sourceowncloud.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.