CISA Adds Seven Actively Exploited Vulnerabilities to KEV Catalog

Seven new entries spanning SQL injection, command injection, authentication failures and request smuggling signal a broad and active threat landscape.

AI-generated illustration depicting vulnerability for the story: CISA Adds Seven Actively Exploited Vulnerabilities to KEV Catalog

Summary

  • CISA has added seven vulnerabilities with confirmed active exploitation to its Known Exploited Vulnerabilities Catalog.
  • Affected products include SonicWall SMA1000, JFrog Artifactory, Sangoma Switchvox, Kestra OSS, BerriAI LiteLLM, and Kludex Starlette.
  • Two SonicWall SMA1000 flaws — an SSRF and an OS command injection — are among the most operationally significant given the appliance’s network edge role.
  • Binding Operational Directive BOD 26-04 requires US federal civilian agencies to prioritise rapid remediation of KEV-listed vulnerabilities on publicly exposed assets.
  • CISA encourages all organisations, not just federal agencies, to treat the KEV Catalog as a prioritisation signal for their own vulnerability management programs.

Seven vulnerabilities, confirmed exploitation

CISA has updated its Known Exploited Vulnerabilities Catalog with seven new entries, each backed by evidence of active exploitation in the wild. The additions span a wide range of vulnerability classes and vendor products, reinforcing that threat actors are not limiting themselves to any single attack technique or technology stack.

What is in the catalog update

The seven newly catalogued vulnerabilities are: a SQL injection flaw in Sangoma Switchvox (CVE-2026-9586); an HTTP request/response smuggling vulnerability in Kludex Starlette (CVE-2026-48710); an OS command injection in Kestra OSS (CVE-2026-49869); an improper authentication issue in BerriAI LiteLLM (CVE-2026-59822); an improper authentication flaw in JFrog Artifactory (CVE-2026-82329); and two vulnerabilities in SonicWall SMA1000 appliances — a server-side request forgery (CVE-2026-83548) and an OS command injection (CVE-2026-83549).

SonicWall SMA1000 warrants immediate attention

The two SonicWall SMA1000 entries will draw the most concern for security teams managing network edge infrastructure. SMA1000 appliances sit at the perimeter of many enterprise environments, handling remote access. A server-side request forgery vulnerability on such a device can allow an attacker to pivot into internal network segments, while an OS command injection on the same platform could hand an adversary full control of the appliance. The combination of both flaws being actively exploited against a single product line is a material risk.

JFrog Artifactory and the software supply chain angle

The improper authentication flaw in JFrog Artifactory is worth calling out separately. Artifactory is widely used as an artefact repository in software development pipelines. Unauthenticated or improperly authenticated access to such a system could enable an attacker to tamper with build artefacts, inject malicious packages, or gain a foothold that reaches far beyond the repository itself. Organisations running Artifactory in their development environments should treat this as a supply chain risk, not simply an infrastructure vulnerability.

AI and modern stack components are not exempt

The inclusion of BerriAI LiteLLM — a proxy and management layer for large language model APIs — is a notable marker of where the threat surface is expanding. As organisations integrate AI tooling into production workflows, the authentication and access controls around those components deserve the same scrutiny as any other externally reachable service. An improper authentication flaw in a platform sitting between users and LLM backends represents a credible pathway for data exposure or abuse.

BOD 26-04 sets the federal baseline

CISA’s Binding Operational Directive BOD 26-04 formally requires US Federal Civilian Executive Branch agencies to prioritise rapid remediation of KEV-listed vulnerabilities, with particular urgency for those on publicly exposed assets where exploitation could grant full control. The directive also sets expectations that agencies check whether a system was compromised before a patch was applied — a step that is often skipped in the rush to patch. Importantly, BOD 26-04 does not extend legal obligations beyond federal agencies, but CISA explicitly encourages all organisations to adopt the same risk-based approach.

A broader signal for enterprise security programs

The KEV Catalog has become one of the most practical prioritisation tools available to security teams, precisely because each entry reflects confirmed exploitation rather than theoretical risk. For organisations already drowning in vulnerability scan output, the catalog offers a defensible, evidence-based filter for triage decisions. The seven new entries suggest that attackers are actively working across legacy telephony systems, developer tooling, AI middleware, and edge appliances — a spread that cuts across most enterprise environments.

Why it matters

For CISOs, the breadth of this catalog update is the key signal. These seven vulnerabilities span edge appliances, developer infrastructure, AI tooling, and legacy communications systems — meaning few organisations will find none of these products in their environment. The SonicWall SMA1000 pair is particularly high-stakes given the appliance’s network position. Equally, the JFrog Artifactory flaw introduces software supply chain risk that can propagate downstream long after the initial exploitation. Active exploitation is confirmed; these are not hypothetical exposures. Prioritising assessment and patching of these specific CVEs is a straightforward, defensible action that should be communicated to relevant asset owners immediately.

What to do now

  • Inventory your environment for all seven affected products: Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances.
  • Prioritise remediation of the two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549) given the appliance’s network edge position and the severity of the vulnerability classes involved.
  • Assess JFrog Artifactory instances for signs of compromise before patching, given the potential for supply chain impact if an attacker has already accessed build artefacts.
  • Apply available patches or mitigations for all seven CVEs in line with vendor guidance, prioritising assets that are publicly exposed.
  • Following CISA’s BOD 26-04 guidance, verify that affected systems were not compromised prior to patching — do not treat patch application as the end of the response process.
  • Review and apply CISA’s risk-based vulnerability management approach — using the KEV Catalog as a primary prioritisation filter — across your broader vulnerability management program.

Sources