ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
28 August 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of