CISA has added seven actively exploited vulnerabilities to its KEV catalog, affecting SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. Threat actors are abusing these flaws to gain admin access, execute commands, deploy reverse shells and miners, steal credentials, and target AI infrastructure for follow-on attacks. #SonicWall #SMA1000 #SangomaSwitchvox #JFrogArtifactory #Starlette #KestraOSS #LiteLLM #Qilin #Agenda #XMRig #CVE-2026-83548 #CVE-2026-83549 #CVE-2026-9586 #CVE-2026-82329 #CVE-2026-48710 #CVE-2026-49869 #CVE-2026-59822 #CVE-2026-42271
Keypoints
- CISA added seven exploited vulnerabilities to its KEV catalog.
- SonicWall confirmed active exploitation of CVE-2026-83548 and CVE-2026-83549.
- Attackers are weaponizing Sangoma Switchvox and JFrog Artifactory flaws for admin access and remote code execution.
- Kestra OSS and LiteLLM are being abused for reverse shells, persistence, credential theft, and crypto mining.
- Federal agencies must patch most issues by September 5, 2026, with Starlette and LiteLLM due by September 16, 2026.
Read More: https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html