VYPR
kevPublished Sep 2, 2026· 1 source

CISA Adds Seven Exploited Vulnerabilities to KEV Catalog, Including SonicWall, Sangoma, and JFrog Flaws

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation across various software and hardware products.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of seven new vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). This update, driven by evidence of active exploitation in the wild, highlights the ongoing threat posed by these flaws to organizations worldwide.

The newly cataloged vulnerabilities span a range of products and exploit types. Among the additions are two critical vulnerabilities affecting SonicWall SMA1000 appliances: CVE-2026-83548, a Server-Side Request Forgery (SSRF) flaw, and CVE-2026-83549, an OS command injection vulnerability. These could allow attackers to gain significant control over affected devices.

Further expanding the list are vulnerabilities in Sangoma Switchvox (CVE-2026-9586, SQL injection), Kludex Starlette (CVE-2026-48710, HTTP request/response smuggling), and Kestra OSS (CVE-2026-49869, OS command injection). These issues represent diverse attack vectors that threat actors are actively leveraging.

Additionally, CISA has added two vulnerabilities related to improper authentication: CVE-2026-59822 affecting BerriAI LiteLLM and CVE-2026-82329 impacting JFrog Artifactory. These authentication bypass flaws can provide unauthorized access to sensitive systems and data.

The inclusion of these vulnerabilities in the KEV Catalog directly supports CISA's Binding Operational Directive (BOD) 26-04. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog, particularly those that grant total control of an asset post-exploitation, on publicly exposed assets.

CISA emphasizes that while BOD 26-04 specifically targets FCEB agencies, all organizations are strongly encouraged to adopt a risk-based vulnerability management approach. Prioritizing the patching of vulnerabilities identified in the KEV Catalog is a crucial step in enhancing overall cybersecurity posture and mitigating the risk of successful cyberattacks.

The agency continues to monitor for actively exploited vulnerabilities and will add them to the KEV Catalog as they meet the established criteria, which include having a CVE ID, documented evidence of exploitation, and clear mitigation guidance. Organizations can submit potential KEV additions through CISA's dedicated nomination form.

Synthesized by Vypr AI