Our Blog

Cybersecurity SOC dashboard comparing CVSS vulnerability severity with EPSS and CISA KEV exploitation signals, highlighting flawed vulnerability prioritisation models

Weekly CISA KEV Updates: 31 August 2026 - 11 New Known Exploited Vulnerabilities Added

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

 

Subscribe to get these articles directly to your inbox when published

 

 

This Week's KEV Additions

CVE ID Vendor / Product CVSS Date Added CISA Due Date Exploitation Type EPSS Score Reachability
CVE-2023-49105 ownCloud / ownCloud 9.8 (Critical) 2026-08-27 2026-08-30 Improper Authentication

11.07%

Remote
CVE-2026-53362 Linux / Kernel 7.8 (High) 2026-08-27 2026-08-30 Privilege Escalation

0.176%

Local / Network Adjacent
CVE-2026-66384 JFrog / Artifactory 6.5 (Medium) 2026-08-27 2026-09-10 Path Traversal

0.579%

Remote (Authenticated)
CVE-2021-23758 Ajax.NET Professional / AjaxPro 9.8 (Critical) 2026-08-26 2026-09-09 Deserialization of Untrusted Data

89.10%

Remote
CVE-2015-3246 Red Hat / libuser 7.0 (High) 2026-08-26 2026-09-16 Race Condition / Privilege Escalation

6.85%

Local
CVE-2015-5287 Red Hat / ABRT 7.0 (High) 2026-08-26 2026-09-16 Privilege Escalation

4.96%

Local
CVE-2022-0995 Linux / Kernel 7.8 (High) 2026-08-26 2026-09-16 Out-of-Bounds Write

32.413%

Local
CVE-2026-8452 Citrix / NetScaler ADC and Gateway 7.5 (High) 2026-08-26 2026-09-16 Improper Restriction of Operations

0.403%

Remote
CVE-2019-1068 Microsoft / SQL Server 8.8 (High) 2026-08-26 2026-09-16 Remote Code Execution

44.66%

Remote
CVE-2026-60004 Gitea / Gitea 8.8 (High) 2026-08-25 2026-09-15 Code Injection 84.554% Remote (Authenticated)
CVE-2026-21962 Oracle / HTTP Server and WebLogic Proxy Plug-in 7.5 (High) 2026-08-24 2026-09-14 Improper Access Control

unknown

Remote

Note: EPSS scores are as published by FIRST.org at time of writing and are not updated after publication; scores change daily.

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

Analysis

 

CVE-2023-49105 — ownCloud / ownCloud

  • What it is: ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known.

  • Affected versions: ownCloud core versions 10.6.0 through 10.13.0

  • Exploitation status: Active exploitation in the wild confirmed.

  • Patch available: Yes, fixed in version 10.13.1.

  • CISA due date: 2026-08-30

  • Operational risk: Complete compromise of sensitive data stores, unauthorized data exfiltration, and file tampering without requiring valid credentials.

 

CVE-2026-53362 — Linux / Kernel

  • What it is: Linux Kernel contains an unspecified vulnerability in the IPv6 networking subsystem allowing local privilege escalation.

  • Affected versions: Multiple Linux kernel distributions.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, updates provided via vendor kernel distribution channels.

  • CISA due date: 2026-08-30

  • Operational risk: Local unprivileged users or compromised low-privilege services can gain root-level control over Linux-based systems.

 

CVE-2026-66384 — JFrog / Artifactory

  • What it is: JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability, allowing writing data outside the Docker cache path.

  • Affected versions: Versions prior to vendor fixed releases.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, official vendor patch available.

  • CISA due date: 2026-09-10

  • Operational risk: Authenticated users can write arbitrary files to restricted host directories, leading to potential software supply chain corruption.

 

CVE-2021-23758 — Ajax.NET Professional / AjaxPro

  • What it is: Ajax.NET Professional contains a deserialization of untrusted data vulnerability allowing remote code execution via arbitrary .NET classes.

  • Affected versions: All versions of package ajaxpro.2.

  • Exploitation status: Active in-the-wild exploitation confirmed.

  • Patch available: Legacy component; mitigation or replacement recommended.

  • CISA due date: 2026-09-09

  • Operational risk: Full unauthenticated system takeover of server host environments running legacy ASP.NET web applications.

 

CVE-2015-3246 — Red Hat / libuser

  • What it is: Red Hat libuser contains a race condition vulnerability allowing corruption of the /etc/passwd file.

  • Affected versions: libuser prior to 0.56.13-8 / 0.60-7.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, patched in supported Linux distribution updates.

  • CISA due date: 2026-09-16

  • Operational risk: Local authenticated users can trigger local denial of service or escalate system privileges to root.

 

CVE-2015-5287 — Red Hat / Automatic Bug Reporting Tool (ABRT)

  • What it is: Red Hat ABRT contains a privilege escalation vulnerability via symlink attack handling crash report files.

  • Affected versions: ABRT versions prior to RHSA-2015:2505 updates.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, Red Hat enterprise security patches available.

  • CISA due date: 2026-09-16

  • Operational risk: Local low-privileged users can overwrite critical system files to gain administrative root privileges.

 

CVE-2022-0995 — Linux / Kernel

  • What it is: Linux Kernel watch_queue subsystem contains an out-of-bounds memory write vulnerability.

  • Affected versions: Linux Kernel versions 5.8 through 5.17-rc7.

  • Exploitation status: Active in-the-wild exploitation confirmed.

  • Patch available: Yes, upstream kernel fixes deployed across distributions.

  • CISA due date: 2026-09-16

  • Operational risk: Local users can gain root access or cause severe host system crashes.

 

CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler Gateway

  • What it is: Citrix NetScaler ADC and NetScaler Gateway contain an improper memory buffer restriction flaw leading to denial of service.

  • Affected versions: NetScaler ADC and Gateway versions prior to fixed security builds.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, Citrix security updates released.

  • CISA due date: 2026-09-16

  • Operational risk: Disruption of network perimeter gateway availability and enterprise remote access capabilities.

 

CVE-2019-1068 — Microsoft / SQL Server

  • What it is: Microsoft SQL Server contains a remote code execution vulnerability due to improper handling of internal function calls.

  • Affected versions: SQL Server 2014, 2016, and 2017 releases.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, Microsoft Cumulative Updates (CU) available.

  • CISA due date: 2026-09-16

  • Operational risk: Remote execution of malicious code in the security context of the SQL Server Database Engine service account.

 

CVE-2026-60004 — Gitea / Gitea

  • What it is: Gitea contains a code injection flaw allowing repository write users to plant malicious Git hooks via the diffpatch API endpoint.

  • Affected versions: Self-hosted Gitea versions prior to 1.27.1.

  • Exploitation status: Active exploitation confirmed.

  • Patch available: Yes, fixed in Gitea release 1.27.1.

  • CISA due date: 2026-09-15

  • Operational risk: Remote execution of shell commands on host servers running Gitea instance services.

 

CVE-2026-21962 — Oracle / HTTP Server and WebLogic Server Proxy Plug-in

  • What it is: Oracle HTTP Server and WebLogic Proxy Plug-in contain an improper access control flaw leading to unauthorized data modification.

  • Affected versions: Oracle Fusion Middleware components prior to vendor patches.

  • Exploitation status: Active in-the-wild exploitation confirmed.

  • Patch available: Yes, released via Oracle Critical Patch Updates.

  • CISA due date: 2026-09-14

  • Operational risk: Unauthenticated remote access and modification of internal application databases and enterprise services.

 

Exploitation Context

This week's additions to the CISA KEV catalog highlight a heavy operational focus on edge infrastructure access and developer environments. Adversaries continue targeting unauthenticated web application entry points such as CVE-2023-49105 (ownCloud) and CVE-2026-21962 (Oracle WebLogic Proxy) to gain an initial foothold without needing valid corporate credentials. Simultaneously, edge network devices running Citrix NetScaler (CVE-2026-8452) remain prime targets for denial-of-service and instability attacks aimed at perimeter services.

 

Once initial footholds are established, threat actors are leveraging both modern and legacy escalation vectors to achieve full system control. Internal repository services like Gitea (CVE-2026-60004) and JFrog Artifactory (CVE-2026-66384) are being weaponized to target development pipelines. Additionally, older kernel and local vulnerabilities such as CVE-2015-3246 and CVE-2022-0995 demonstrate that legacy technical debt continues to provide reliable pathways for local privilege escalation.

 

 

Remediation Priorities

 

Priority CVE ID Recommended Action Timeline
1 CVE-2023-49105 Upgrade ownCloud core to 10.13.1 or delete graphapi app per vendor instructions. Immediate
2 CVE-2021-23758 Replace or update legacy AjaxPro library instances across target web apps. Within 24 hours
3 CVE-2026-60004 Update Gitea instances to release 1.27.1 or higher. Within 24 hours
4 CVE-2026-21962 Apply Oracle Critical Patch Update for HTTP Server and WebLogic Proxy. Within 24 hours
5 CVE-2019-1068 Apply Microsoft SQL Server cumulative security updates across database hosts. Within 72 hours
6 CVE-2026-8452 Apply Citrix firmware updates to NetScaler ADC and Gateway appliances. Within 72 hours
7 CVE-2026-53362 Apply updated Linux kernel packages provided by distribution vendor. By CISA due date
8 CVE-2026-66384 Patch JFrog Artifactory to the latest secure version. By CISA due date
9 CVE-2022-0995 Update Linux kernel packages across affected Linux infrastructure. By CISA due date
10 CVE-2015-3246 Update libuser library packages on Red Hat systems. By CISA due date
11 CVE-2015-5287 Update ABRT package components via standard repository updates. By CISA due date

 

 

Detection and Monitoring Guidance

 

  • CVE-2023-49105 (ownCloud):

    • Log Sources: Web server access logs (Nginx/Apache), ownCloud audit logs.

    • Behavioral Indicators: Requests reaching `apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php` or unauthenticated WebDAV calls.

    • Monitoring Gap / Detection Artifacts: Disclosure of environment variables containing system secrets and administrative credentials.

 

  • CVE-2026-53362 (Linux):

    • Log Sources: Linux kernel syslog (`/var/log/messages`, `journalctl`), Endpoint Detection and Response (EDR) telemetry.

    • Behavioral Indicators: Abnormal memory fault logs in IPv6 stack calls, rapid local privilege elevation attempts.

    • Monitoring Gap / Detection Artifacts: Kernel crash panics and unexpected process privileges granted to local accounts.

 

  • CVE-2026-66384 (JFrog):

    • Log Sources: Artifactory access logs, request logs (`artifactory-service.log`).

    • Behavioral Indicators: API calls targeting Docker endpoints containing path traversal character sequences (`../`).

    • Monitoring Gap / Detection Artifacts: Files created outside the designated Docker cache storage directory.

 

  • CVE-2021-23758 (AjaxPro):

    • Log Sources: IIS W3C logs, Web Application Firewall (WAF) logs.

    • Behavioral Indicators: HTTP POST requests containing serialized object payloads sent to AjaxPro HTTP handlers (`ajaxpro/*.ashx`).

    • Monitoring Gap / Detection Artifacts: Spawning of child command shells (`cmd.exe`, `powershell.exe`) directly under IIS worker process (`w3wp.exe`).

 

  • CVE-2015-3246 (Red Hat):

    • Log Sources: Auditd logs, Linux authentication logs (`/var/log/secure`).

    • Behavioral Indicators: Rapid, repeated execution of `/usr/sbin/userhelper` or file modification triggers targeting `/etc/passwd`.

    • Monitoring Gap / Detection Artifacts: Malformed entries or unexpected structural changes in `/etc/passwd`.

 

  • CVE-2015-5287 (Red Hat):

    • Log Sources: System audit logs, ABRT service logs.

    • Behavioral Indicators: Symbolic links created inside temporary crash reporting directories pointing to protected system paths.

    • Monitoring Gap / Detection Artifacts: Unexpected file write operations performed by `abrt-hook-ccpp`.

 

  • CVE-2022-0995 (Linux):

    • Log Sources: Host kernel audit logs, EDR process execution logs.

    • Behavioral Indicators: Kernel memory out-of-bounds error logs during `watch_queue` notification function calls.

    • Monitoring Gap / Detection Artifacts: Local unprivileged user processes suddenly changing privilege levels to UID 0.

 

  • CVE-2026-8452 (Citrix):

    • Log Sources: NetScaler system syslog files, NSIP management logs.

    • Behavioral Indicators: Malformed incoming network traffic targeting AAA virtual servers or Gateway endpoints resulting in process restarts.

    • Monitoring Gap / Detection Artifacts: High memory usage alerts or sudden core dumps produced by NetScaler packet engines.

 

  • CVE-2019-1068 (Microsoft):

    • Log Sources: SQL Server error logs, Windows Event Logs (Application & System).

    • Behavioral Indicators: Command execution requests originating from SQL Server database process context.

    • Monitoring Gap / Detection Artifacts: `sqlservr.exe` spawning unexpected external binaries or shell instances.

 

  • CVE-2026-60004 (Gitea):

    • Log Sources: Gitea HTTP server logs, host file access logs.

    • Behavioral Indicators: Malicious HTTP calls sent to `/api/v1/repos/{owner}/{repo}/diffpatch`.

    • Monitoring Gap / Detection Artifacts: Newly generated executable hook scripts residing within `.git/hooks/` folders.

 

  • CVE-2026-21962 (Oracle):

    • Log Sources: Oracle HTTP Server access logs, WebLogic Proxy plugin log files.

    • Behavioral Indicators: Anomalous HTTP request headers attempting to bypass access control checks on proxy routes.

    • Monitoring Gap / Detection Artifacts: Unauthorized administrative data modification entries on backend WebLogic instances.

 

 

Hackerstorm Analysis

This week's KEV updates emphasize that threat actors continue to target enterprise application gateways and developer infrastructure to establish initial footholds. With high-severity bugs identified across widely deployed products like ownCloud, Citrix NetScaler, and Oracle WebLogic Proxy components, organizations face significant risk of initial access exploitation. Once inside, attackers are increasingly relying on both recent and legacy local privilege escalation vulnerabilities, such as older Red Hat utilities and kernel bugs, to gain complete administrative dominance over target hosts. Immediate remediation of public-facing services alongside host-level patching is critical to interrupt active kill chains.

 

 

What you should do next

Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities.  View all weekly reports here

 

 

 

 

Further Reading

The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.

 

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

 

 

 

 


About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

 

Primary vulnerability data

 

 

Vendor and technical references

 

 


 

Analyst Notes

  • No ransomware attribution was publicly associated with this week's KEV additions at the time of publication.
  • No confirmed threat actor attribution was available beyond CISA's confirmation of active exploitation for the majority of entries.
  • Where vendor advisory details or EPSS values were unavailable at publication time, placeholders were retained pending analyst validation and vendor updates prior to final publication.

 

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy