CISA Adds Seven Actively Exploited Flaws to KEV Catalog
The catalog update includes SonicWall SMA 1000 flaws CVE-2026-83548 and CVE-2026-83549, Sangoma Switchvox SQL injection flaw CVE-2026-9586, and JFrog Artifactory authentication flaw CVE-2026-82329. It also lists Kludex Starlette request-smuggling flaw CVE-2026-48710, Kestra command-injection flaw CVE-2026-49869 and Berri LiteLLM authentication flaw CVE-2026-59822. Reported CVSS scores range from 6.5 to 10.0.
SonicWall said it investigated a case indicating active exploitation of the two SMA 1000 vulnerabilities. The server-side request forgery issue can give an unauthenticated remote attacker access to sensitive functions, while the command-injection issue can let an authenticated administrator run operating-system commands. BleepingComputer reported that attackers chained the flaws in remote code execution attacks.
Separate research described exploitation of Switchvox and Artifactory to install reverse shells or create administrative tokens. The Artifactory weakness affects default configurations reachable over a network, while the Switchvox flaw permits crafted requests to execute SQL statements against the PostgreSQL backend and can lead to code execution. Administrators should treat internet-facing management and application interfaces as the highest-priority exposure.
Microsoft linked CVE-2026-49869 to a Kestra compromise involving workflow-driven shell execution, Docker environment discovery, XMRig deployment and data collection. Its investigation also described attacks on LiteLLM gateways that sought provider keys, database records and persistent access. Microsoft advised defenders to inventory exposed AI management surfaces, restrict administrative access and monitor for shell execution and secret access originating from those workloads.
The CISA deadlines reported for federal civilian agencies are September 5 for five flaws and September 16 for the Starlette and LiteLLM issues. Organizations outside the federal government can use the same deadlines to prioritize remediation: identify affected versions, apply vendor updates, remove unnecessary internet exposure, rotate credentials if compromise is suspected and review logs for unexpected token creation, workflow execution, reverse shells or cryptocurrency-mining activity.