CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

August 28, 2026

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body Ravie LakshmananAug 28, 2026Vulnerability / Cyber Espionage The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured, which is the default configuration. Disclosed by ownCloud in November 2023, the issue impacts…

CVEs: CVE-2023-49105, CVE-2024-28000, CVE-2026-53362, CVE-2026-66384, CVE-2026-58231