Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: kev (4 articles)Clear

CISA flags exploited ownCloud flaw that lets attackers read and delete files

CISA added a critical ownCloud flaw to its exploited-vulnerabilities catalog after attackers used it to steal data from a research organization. Tracked as CVE-2023-49105 and scored 9.8, the WebDAV authentication-bypass bug lets an unauthenticated attacker who knows a victim's username read, modify, or delete that user's files when no signing key is configured, which is the platform's default. Disclosed back in November 2023, it affects ownCloud Server core versions 10.6.0 through 10.13.0 and was fixed in 10.13.1, yet unpatched instances remain exposed nearly two years later. Public exploit code exists, and CISA set a short deadline for federal agencies, underscoring that long-standing self-hosted flaws keep getting weaponized.

Check
Upgrade ownCloud Server to 10.13.1 or later now, or configure a signing key as a mitigation, and review WebDAV access logs for unusual file reads, changes, or deletions.
Affected
Organizations running ownCloud Server 10.6.0 through 10.13.0 without a signing key, the default (CVE-2023-49105); an unauthenticated attacker knowing a username can read, alter, or delete that user's files, and exploitation is active.
Fix
Patch to 10.13.1, set a signing key, restrict and monitor exposed WebDAV services, investigate for unauthorized file access or deletion, and treat any long-unpatched ownCloud instance as a likely target.

Attackers exploit a critical Gitea flaw to run code on self-hosted Git servers

CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.

Check
Upgrade Gitea to 1.27.1 or later immediately, disable open self-registration on internet-facing instances, and treat any exposed, registration-enabled server as an incident-response case rather than just a patch.
Affected
Organizations running self-hosted Gitea 1.17 through 1.27.0 (CVE-2026-60004); an attacker with repository write access, obtainable through default open registration, can execute shell commands as the Gitea service account.
Fix
Patch to a fixed release, turn off self-registration where not needed, restrict internet exposure of Gitea, and hunt patched servers for rogue Git hooks, miner processes, and other signs of compromise.

Ransomware gangs now exploit a Windows Task Host flaw to gain SYSTEM

CISA confirmed that ransomware groups are now exploiting a Windows Task Host privilege-escalation flaw that has been flagged as actively exploited since April. Tracked as CVE-2025-60710 and scored 7.8, it is a link-following weakness in the component that runs background scheduled tasks as SYSTEM: a local attacker with only basic user rights can use a junction on a user-writable path to make a SYSTEM-level task act on files it should not, escalating to full control. Microsoft patched it in November 2025, and it affects Windows 11 and Server 2025. Privilege escalation like this is exactly what ransomware operators need to disable defenses and spread after gaining an initial foothold.

Check
Confirm the November 2025 update for this flaw is deployed across Windows 11 and Windows Server 2025 systems, prioritizing any that still lack it, since ransomware crews are now using it.
Affected
Windows 11 and Windows Server 2025 systems missing the November 2025 patch (CVE-2025-60710); a local attacker with basic rights can escalate to SYSTEM, and ransomware groups are actively exploiting it.
Fix
Apply the patch, prioritize privilege-escalation fixes in your patching since they enable ransomware to spread, monitor for junction abuse and unexpected SYSTEM-level file operations, and limit local footholds through least privilege.

Progress Kemp LoadMaster command injection flaw added to KEV after active exploitation

CISA added a critical Progress Kemp LoadMaster flaw to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Tracked as CVE-2026-8037 and scored 9.6, it is a command injection bug that lets an unauthenticated attacker run arbitrary commands on the load balancer appliance through unsanitized input in several command endpoints. watchTowr traced it to improper handling of user input in a quote-escaping function. Telemetry recorded 792 exploitation attempts over 41 days from 65 addresses across 18 countries, with activity as recent as early August. Federal agencies were directed to patch by August 10, a useful signal of urgency for everyone else.

Check
Patch Progress Kemp LoadMaster appliances to the fixed release now, and because the appliance sits inline with traffic, review it for signs of command execution and unexpected configuration changes.
Affected
Organizations running unpatched Progress Kemp LoadMaster (CVE-2026-8037); an unauthenticated attacker can execute arbitrary commands on an appliance that sits inline with network traffic, and exploitation is ongoing.
Fix
Apply the vendor patch, restrict management access to the appliance, hunt for unauthorized commands and configuration changes, and rotate any credentials the load balancer stored or handled.