# CISA adds 7 exploited flaws to KEV catalog

Published: 2026-09-02 · Severity: severe · Sectors: government-national, technology, telecommunications
Canonical: https://vorant.io/reports/62a5a678-b0dd-5fd5-9436-567119acf945/cisa-adds-7-exploited-flaws-to-kev-catalog

> CISA added seven actively exploited vulnerabilities affecting Sangoma, Starlette, Kestra, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 to its KEV catalog.

CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with seven new entries, citing evidence of active exploitation in the wild. The affected products span a range of software categories including a VoIP platform (Sangoma Switchvox), a Python web framework (Starlette), a workflow orchestration tool (Kestra OSS), an LLM gateway (BerriAI LiteLLM), an artifact repository manager (JFrog Artifactory), and enterprise remote access appliances (SonicWall SMA1000). Vulnerability types include SQL injection, HTTP request/response smuggling, OS command injection, improper authentication, and SSRF — all common vectors for gaining unauthorized access or executing arbitrary commands on affected systems.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on internet-exposed assets, particularly those that grant full post-exploitation control, and to verify whether systems were compromised prior to patching. While the directive is mandatory only for FCEB agencies, CISA urges all organizations to adopt similar risk-based patching practices given the confirmed exploitation of these flaws.

Defenders should inventory their environments for any of the seven affected products and apply vendor patches or mitigations immediately. Given the diversity of affected software and the presence of two chained SonicWall SMA1000 flaws (SSRF and OS command injection), organizations using SonicWall remote access appliances should treat this as a priority for investigation and compromise assessment.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48710 (KEV), CVE-2026-49869 (KEV), CVE-2026-59822 (KEV), CVE-2026-82329 (KEV), CVE-2026-83548 (KEV), CVE-2026-83549 (KEV), CVE-2026-9586 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/62a5a678-b0dd-5fd5-9436-567119acf945/cisa-adds-7-exploited-flaws-to-kev-catalog.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
