Back to feed

CISA Adds Seven Exploited Flaws to KEV Catalog

2 min
CISA Adds Seven Exploited Flaws to KEV Catalog

This digest was compiled by AI from multiple sources — links to the originals are below.

The U.S. Cybersecurity and Infrastructure Security Agency added seven security flaws to its Known Exploited Vulnerabilities catalog on Wednesday. The additions follow active exploitation of SonicWall SMA 1000 flaws and weaponization of Sangoma Switchvox and JFrog Artifactory vulnerabilities. Attackers have deployed reverse shells and minted admin tokens for follow-on enumeration.

Key Facts

  • CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on Wednesday.
  • CVE-2026-83548 and CVE-2026-83549 affect SonicWall SMA 1000 Appliances and have CVSS scores of 10.0 and 7.8 respectively.
  • CVE-2026-9586 in Sangoma Switchvox and CVE-2026-82329 in JFrog Artifactory have been weaponized to deploy reverse shells and mint admin tokens.
  • CVE-2026-48710 in Kludex Starlette can be chained with CVE-2026-42271 in Berri LiteLLM to bypass authentication and achieve remote code execution.
  • CVE-2026-42271 was added to CISA's KEV catalog around the same time as the seven new additions.

The Vulnerabilities

CISA added seven security flaws to its Known Exploited Vulnerabilities catalog on Wednesday. The list includes CVE-2026-83548, a server-side request forgery vulnerability in SonicWall SMA 1000 Appliances with a CVSS score of 10.0. CVE-2026-83549 is a post-authentication OS command injection vulnerability in the same product with a CVSS score of 7.8. CVE-2026-9586 is an SQL injection vulnerability in Sangoma Switchvox with a CVSS score of 9.3. CVE-2026-82329 is an improper authentication vulnerability in JFrog Artifactory with a CVSS score of 9.8.

Active Exploitation

SonicWall disclosed that it investigated a case indicating active exploitation of CVE-2026-83548 and CVE-2026-83549. According to reports from Horizon3.ai and watchTowr, unknown threat actors have weaponized CVE-2026-9586 and CVE-2026-82329 to deploy reverse shells and mint admin tokens. The attackers used the admin tokens for follow-on enumeration of users, groups, credential sets, and federated access topologies. A report from Horizon3.ai in June 2026 revealed that CVE-2026-48710 could be chained with CVE-2026-42271 to bypass authentication and achieve remote code execution against vulnerable LiteLLM deployments. CVE-2026-42271 was added to CISA's KEV catalog around the same time as the seven new additions.

Remaining Flaws

CVE-2026-48710 is an HTTP request/response smuggling vulnerability in Kludex Starlette with a CVSS score of 6.5. CVE-2026-49869 is an OS command injection vulnerability in Kestra OSS with a CVSS score of 10.0. CVE-2026-59822 is an improper authentication vulnerability in Berri LiteLLM's Model Context Protocol Streamable HTTP endpoint with a CVSS score of 8.8.

1 source

Time · lag behind first