VORANT. Threat Intelligence Sign in Get the full feed

CISA adds 7 exploited flaws to KEV catalog

severe vulnerability government-nationaltechnologytelecommunications

CISA added seven actively exploited vulnerabilities affecting Sangoma, Starlette, Kestra, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 to its KEV catalog.

CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with seven new entries, citing evidence of active exploitation in the wild. The affected products span a range of software categories including a VoIP platform (Sangoma Switchvox), a Python web framework (Starlette), a workflow orchestration tool (Kestra OSS), an LLM gateway (BerriAI LiteLLM), an artifact repository manager (JFrog Artifactory), and enterprise remote access appliances (SonicWall SMA1000). Vulnerability types include SQL injection, HTTP request/response smuggling, OS command injection, improper authentication, and SSRF — all common vectors for gaining unauthorized access or executing arbitrary commands on affected systems.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on internet-exposed assets, particularly those that grant full post-exploitation control, and to verify whether systems were compromised prior to patching. While the directive is mandatory only for FCEB agencies, CISA urges all organizations to adopt similar risk-based patching practices given the confirmed exploitation of these flaws.

Defenders should inventory their environments for any of the seven affected products and apply vendor patches or mitigations immediately. Given the diversity of affected software and the presence of two chained SonicWall SMA1000 flaws (SSRF and OS command injection), organizations using SonicWall remote access appliances should treat this as a priority for investigation and compromise assessment.

Mentioned in this report

Vulnerabilities CVE-2026-48710KEVCVE-2026-49869KEVCVE-2026-59822KEVCVE-2026-82329KEVCVE-2026-83548KEVCVE-2026-83549KEVCVE-2026-9586KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free