【Vulnerability Alert】CISA Added 11 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/24-2026/08/30)

publish date : 2026-09-30 update date : 2026-09-30

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026091411093131 Publication Time 2026-09-14 11:36:32
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-14 11:36:32
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 11 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/24-2026/08/30)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000008

【CVE-2026-21962】Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in Improper Access Control Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an Improper Access Control vulnerability, which may allow unauthorized users to obtain permissions to create, delete, or modify critical data, as well as unauthorized access to critical data, and may even result in full access to all data accessible by Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.

【CVE-2026-60004】Gitea Code Injection Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Gitea contains a Code Injection vulnerability. An attacker with repository write permissions may send a malicious patch to the diffpatch API endpoint to implant an executable Git hook and execute Shell commands as the Gitea service account.

【CVE-2021-23758】Ajax.NET Professional Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 8.1)
【Whether exploited by ransomware: Unknown】Ajax.NET Professional (AjaxPro) contains a Deserialization of Untrusted Data vulnerability, which may allow an attacker to execute remote code by leveraging arbitrary .NET classes. The affected products may have reached End-of-Life (EoL) and/or End-of-Support (EoS). Users are advised to discontinue use of the affected products and/or migrate to supported versions.

【CVE-2015-3246】Red Hat Libuser Race Condition Vulnerability (CVSS v3.1: 5.1)
【Whether exploited by ransomware: Unknown】Red Hat libuser contains a Race Condition vulnerability that allows an authenticated local user to corrupt the /etc/passwd file, potentially resulting in denial of service or privilege escalation.

【CVE-2015-5287】Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability (CVSS v3.1: 7.8)
【Whether exploited by ransomware: Unknown】Red Hat Automatic Bug Reporting Tool (ABRT) contains a Privilege Escalation vulnerability, which may allow a local user with specific privileges to obtain elevated privileges through a symbolic link attack against files with predictable names. The affected products may have reached End-of-Life (EoL) and/or End-of-Support (EoS). Users are advised to discontinue use of the affected products and/or migrate to supported versions.

【CVE-2022-0995】Linux Kernel Out-of-Bounds Write Vulnerability (CVSS v3.1: 7.8)
【Whether exploited by ransomware: Unknown】Linux Kernel contains an Out-of-Bounds Write vulnerability, which may allow a local user to obtain privileged access or cause a denial-of-service condition.

【CVE-2026-8452】Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Citrix NetScaler ADC and NetScaler Gateway contain an Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability, which may result in denial of service.

【CVE-2019-1068】Microsoft SQL Server Remote Code Execution Vulnerability (CVSS v3.1: 8.8)
【Whether exploited by ransomware: Unknown】Microsoft SQL Server contains a Remote Code Execution vulnerability, which may allow an attacker to execute code as the SQL Server Database Engine service account.

【CVE-2023-49105】ownCloud Improper Authentication Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】ownCloud contains an Improper Authentication vulnerability. If an attacker knows the victim's username and the victim has not configured a signing key, the attacker may access, modify, or delete any file without authentication.

【CVE-2026-53362】Linux Kernel Unspecified Vulnerability (CVSS v3.1: 7.8)
【Whether exploited by ransomware: Unknown】Linux Kernel contains an unspecified vulnerability that may allow an attacker to escalate privileges through the IPv6 networking subsystem. This vulnerability may affect multiple products, including but not limited to Suse, Red Hat, and other products that use Linux.

【CVE-2026-66384】JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability (CVSS v3.1: 5.3)
【Whether exploited by ransomware: Unknown】JFrog Artifactory contains an Improper Limitation of a Pathname to a Restricted Directory vulnerability. Under specific remote repository conditions, this vulnerability may allow an authenticated user to write data outside the intended Docker cache path.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-21962】Please refer to the affected versions listed by the official vendor https://www.oracle.com/security-alerts/cpujan2026.html

【CVE-2026-60004】Please refer to the affected versions listed by the official vendor https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m

【CVE-2021-23758】Please refer to the affected versions listed by the official vendor https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57

【CVE-2015-3246】Please refer to the affected versions listed by the official vendor https://access.redhat.com/articles/1537873

【CVE-2015-5287】Please refer to the affected versions listed by the official vendor https://access.redhat.com/errata/RHSA-2015:2505.html

【CVE-2022-0995】Please refer to the affected versions listed by the official vendor https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb

【CVE-2026-8452】Please refer to the affected versions listed by the official vendor https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

【CVE-2019-1068】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068

【CVE-2023-49105】Please refer to the affected versions listed by the official vendor https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/

【CVE-2026-53362】Please refer to the affected versions listed by the official vendor https://lore.kernel.org/linux-cve-announce/2026070450-CVE-2026-53362-fe9b@gregkh/T/#u

【CVE-2026-66384】Please refer to the affected versions listed by the official vendor https://docs.jfrog.com/releases/docs/jfrog-security-advisories

[Recommended Actions]

【CVE-2026-21962】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://www.oracle.com/security-alerts/cpujan2026.html

【CVE-2026-60004】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m

【CVE-2021-23758】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57

【CVE-2015-3246】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://access.redhat.com/articles/1537873

【CVE-2015-5287】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://access.redhat.com/errata/RHSA-2015:2505.html

【CVE-2022-0995】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb

【CVE-2026-8452】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

【CVE-2019-1068】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068

【CVE-2023-49105】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/

【CVE-2026-53362】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://lore.kernel.org/linux-cve-announce/2026070450-CVE-2026-53362-fe9b@gregkh/T/#u

【CVE-2026-66384】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://docs.jfrog.com/releases/docs/jfrog-security-advisories

 

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center