CISA Adds Seven Exploited Vulnerabilities to KEV Catalog, Including SonicWall, Sangoma, and JFrog Flaws
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation across various software and hardware products.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of seven new vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). This update, driven by evidence of active exploitation in the wild, highlights the ongoing threat posed by these flaws to organizations worldwide.
The newly cataloged vulnerabilities span a range of products and exploit types. Among the additions are two critical vulnerabilities affecting SonicWall SMA1000 appliances: CVE-2026-83548, a Server-Side Request Forgery (SSRF) flaw, and CVE-2026-83549, an OS command injection vulnerability. These could allow attackers to gain significant control over affected devices.
Further expanding the list are vulnerabilities in Sangoma Switchvox (CVE-2026-9586, SQL injection), Kludex Starlette (CVE-2026-48710, HTTP request/response smuggling), and Kestra OSS (CVE-2026-49869, OS command injection). These issues represent diverse attack vectors that threat actors are actively leveraging.
Additionally, CISA has added two vulnerabilities related to improper authentication: CVE-2026-59822 affecting BerriAI LiteLLM and CVE-2026-82329 impacting JFrog Artifactory. These authentication bypass flaws can provide unauthorized access to sensitive systems and data.
The inclusion of these vulnerabilities in the KEV Catalog directly supports CISA's Binding Operational Directive (BOD) 26-04. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog, particularly those that grant total control of an asset post-exploitation, on publicly exposed assets.
CISA emphasizes that while BOD 26-04 specifically targets FCEB agencies, all organizations are strongly encouraged to adopt a risk-based vulnerability management approach. Prioritizing the patching of vulnerabilities identified in the KEV Catalog is a crucial step in enhancing overall cybersecurity posture and mitigating the risk of successful cyberattacks.
The agency continues to monitor for actively exploited vulnerabilities and will add them to the KEV Catalog as they meet the established criteria, which include having a CVE ID, documented evidence of exploitation, and clear mitigation guidance. Organizations can submit potential KEV additions through CISA's dedicated nomination form.
CISA has officially added two SonicWall SMA1000 vulnerabilities, CVE-2026-83549 (OS command injection) and CVE-2026-83548 (SSRF), to its Known Exploited Vulnerabilities catalog. This confirms active exploitation in the wild, prompting a mandatory remediation deadline of September 5, 2026, for federal agencies and emphasizing the need for forensic triage due to the potential for deep network compromise.
This update details the specific threat actor activities and technical impacts associated with the seven vulnerabilities added to CISA's KEV catalog. Threat actors are observed deploying reverse shells and crypto miners, and in some cases, minting admin tokens for further enumeration. Notably, the exploitation of CVE-2026-49869 in Kestra OSS is linked to establishing a reverse shell, conducting environment discovery, and deploying a cryptocurrency miner, with data harvesting as a follow-on objective. Additionally, the exploitation chain involving CVE-2026-42271 and CVE-2026-48710 against LiteLLM gateways is used to deliver an XMRig miner after fingerprinting the host and terminating competing processes.
The new article provides further technical details on the exploitation of CVE-2026-9586, a critical SQL injection vulnerability affecting Sangoma Switchvox SMB Edition. Researchers observed attackers injecting malicious SQL commands via an unauthenticated HTTP endpoint to achieve remote code execution, deploying reverse shells and conducting reconnaissance. Approximately 4,000 vulnerable devices were identified online, with Sangoma having released version 8.4.0.2 to address the flaw.