CISA adds three known exploited vulnerabilities
On 2026-08-27 CISA added three CVEs to its Known Exploited Vulnerabilities catalog. The headline entry is CVE-2023-49105, an improper authentication vulnerability in ownCloud carrying a CVSS score of 9.8. An authentication bypass on a file sharing platform is exactly the kind of thing attackers chain into full data access, so if you run ownCloud anywhere, this moves from patch eventually to patch now.
The other two additions are CVE-2026-53362, an unspecified Linux kernel vulnerability rated 7.8, and CVE-2026-66384, a path traversal flaw in JFrog Artifactory rated 5.3. None of the three are marked ransomware-linked at this point, but KEV listing means confirmed exploitation in the wild. Federal agencies have remediation deadlines and everyone else should treat a KEV add as the signal to act.
Citrix NetScaler CVE-2026-8452 exploited in the wild
Both SecurityWeek and Help Net Security reported on 2026-08-27 that a previously patched Citrix NetScaler ADC and Gateway flaw, CVE-2026-8452, is now being exploited in the wild. If you patched when the fix first shipped you are covered, but plenty of NetScaler appliances lag behind. Confirm your build and check for signs of compromise, not just the patch level.
This fits a broader pattern. Tenable published research on 2026-08-26 showing edge infrastructure under sustained attack, naming SonicWall SMA1000 CVE-2026-15409 alongside older perimeter bugs in Palo Alto, Check Point, Ivanti, and Fortinet gear. The lesson is consistent: internet-facing appliances get scanned and hit fast, and old CVEs like CVE-2024-3400 and CVE-2024-47575 keep showing up in real intrusions.
Hot movers worth your attention
Several KEV-listed CVEs are drawing heavy exploitation interest. Ransomware-linked entries top the list, and these deserve priority in any triage queue:
- CVE-2026-15409, SonicWall SMA1000 server-side request forgery, CVSS 10, KEV listed and ransomware-linked, EPSS 0.84.
- CVE-2026-35273, Oracle PeopleSoft Enterprise PeopleTools missing authentication, CVSS 9.8, ransomware-linked, EPSS 0.95.
- CVE-2026-41940, WebPros cPanel and WHM missing authentication, CVSS 9.8, ransomware-linked, EPSS 0.99.
- CVE-2026-45659, Microsoft SharePoint remote code execution, CVSS 8.8, KEV listed and ransomware-linked, EPSS 0.76.
- CVE-2026-21962, Oracle HTTP Server and WebLogic proxy plug-in improper access control, CVSS 10, KEV listed.
Windows updates and ICS advisories
On the Microsoft side, the top-ranked cumulative updates this cycle include KB5046698 for Windows Server 2022 covering 37 CVEs and KB5046696 for Windows 10 Version 1809 covering 36 CVEs, both flagged Critical and both containing KEV-listed content. If your patch rings are behind on these, they carry known-exploited fixes, not just routine hardening.
CISA also published a batch of industrial control system advisories on 2026-08-27, covering Applied Systems Engineering ASE2000, All-Line Equipment Fuel-Boss, Ebyte NA111-M, Xiiaozet LK100W, and updates to Mitsubishi Electric FA products and CNC Series. If you operate any of that equipment, review the specific advisories.
Do this first
Work the newest confirmed exploitation before anything else.
- Patch or isolate ownCloud for CVE-2023-49105 and confirm your Linux kernel and JFrog Artifactory status against the two other KEV adds.
- Verify NetScaler ADC and Gateway builds against CVE-2026-8452 and hunt for compromise, since the fix predates the exploitation.
- Prioritize the ransomware-linked movers: SonicWall, Oracle PeopleSoft, cPanel, and SharePoint.
- Confirm KB5046698 and KB5046696 are deployed across your Windows fleet.
- The free Microsoft Patch Tracker from Siemserva by Senserva ranks your open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker in Siemserva follows KEV additions daily so you can check the ownCloud and NetScaler items against your own estate.
Sources
- CISA Cybersecurity Advisories: CISA Adds Three Known Exploited Vulnerabilities to Catalog (2026-08-27)
- SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild (2026-08-27)
- Help Net Security: Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) (2026-08-27)
- Tenable: Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter (2026-08-26)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-08-29.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.