Government Advisory

US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them

CISA · 27 Aug 2026
Key Takeaway If your business uses ownCloud, Linux servers, or JFrog Artifactory, check for and apply security patches immediately, as these flaws are being actively exploited by attackers.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added three new security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that hackers are actively using them in real-world attacks. The affected products include ownCloud (a file-sharing platform), the Linux kernel, and JFrog Artifactory (a software package management tool).

While the KEV Catalog is primarily designed to guide US federal agencies on which vulnerabilities to patch first, it's a valuable resource for any business worldwide. Vulnerabilities on this list aren't theoretical risks — they are actively being exploited by cybercriminals right now, making them a priority for any organisation using the affected software.

If your business uses ownCloud for file sharing, runs Linux-based servers, or relies on JFrog Artifactory for managing software packages, it's important to check with your IT provider or software vendor whether you're running a vulnerable version and apply the necessary security updates as soon as possible.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.