Nine vulnerabilities entered the exploited catalogue in two days
CISA added three vulnerabilities to its catalogue of known exploited vulnerabilities on 27 August 2026. Six others had gone in the day before, which makes nine entries across the two days. The three latest cover ownCloud, the Linux kernel and JFrog Artifactory.
CVE-2023-49105 in ownCloud concerns improper authentication. CVE-2026-53362 in the Linux kernel is listed without further description. CVE-2026-66384 in JFrog Artifactory concerns improper limitation of a pathname to a restricted directory. Among the six from the day before is CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway, a memory handling flaw that Citrix itself describes as denial of service, and where the security company watchTowr has shown that it can also yield unauthenticated code execution as root. A vulnerability enters the catalogue only where there is evidence that someone is actually exploiting it.
What this means for you if you run your own servers
Notice what kind of systems these are. A file sharing server, a kernel and a repository for build artefacts rarely sit at the outer edge facing the internet, so they rarely come first in a patching plan. Our assessment is that this is precisely why they turn up here. Flaws like these become useful to an attacker who has already got in somewhere.
The second question is who owns these systems where you work. Artifactory tends to be set up by the developers, ownCloud appears because somebody needed file sharing quickly, and the kernel is patched by whoever runs the machine. If you cannot put a name to each of them, that gap is what decides how long the update takes. The Citrix entry belongs in a different category, because that appliance sits at the edge and terminates access for employees and customers alike.
Berigo recommends
- Establish whether you run ownCloud, JFrog Artifactory or an affected Linux kernel, and write the answer down.
- Put a name to who owns each system, and to who installs the update.
- Take Citrix NetScaler first if you have such appliances, since the flaw can be exploited without logging in.
- Look for traces in logs from before the update was installed, not only afterwards.
- Let internal servers into vulnerability management on the same terms as anything facing the internet.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch