rootpwn

Threat Intel

CISA Expands KEV Catalog with Seven Fresh Exploited Vulnerabilities

CISA has just added seven new CVEs to its Known Exploited Vulnerabilities (KEV) catalog, all confirmed to be actively exploited in the wild. The list includes SQL injection in Sangoma Switchvox, HTTP smuggling in Kludex Starlette, OS command injection in Kestra OSS, and several high‑impact flaws in BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. Under BOD 26‑04, federal agencies must prioritize patching these high‑risk items on publicly exposed assets, while the broader community is urged to adopt the same risk‑based approach and submit any missing exploited CVEs for incl

In a rapid move to tighten the federal cyber posture, the Cybersecurity and Infrastructure Security Agency (CISA) has broadened its Known Exploited Vulnerabilities (KEV) catalog with seven newly confirmed, actively exploited CVEs. These flaws span a range of attack vectors—from SQL injection to OS command injection—and threaten critical infrastructure and enterprise systems alike.

New KEV Additions

  • CVE‑2026‑9586 – Sangoma Switchvox SQL injection that can lead to data exfiltration or system takeover.
  • CVE‑2026‑48710 – Kludex Starlette HTTP request/response smuggling enabling stealthy data manipulation.
  • CVE‑2026‑49869 – Kestra OSS OS command injection exposing the underlying host to arbitrary code execution.
  • CVE‑2026‑59822 – BerriAI LiteLLM improper authentication flaw granting unauthorized access to AI workloads.
  • CVE‑2026‑82329 – JFrog Artifactory improper authentication vulnerability that can expose build artifacts.
  • CVE‑2026‑83548 – SonicWall SMA1000 appliance server‑side request forgery allowing attackers to hijack internal traffic.
  • CVE‑2026‑83549 – SonicWall SMA1000 OS command injection that can compromise the device’s operating system.

Why It Matters

These weaknesses are frequent targets for malicious actors, offering a direct path to full control of exposed assets. Under Binding Operational Directive (BOD) 26‑04, federal civilian agencies are mandated to prioritize rapid remediation of such high‑risk vulnerabilities—especially those that grant total control post‑exploitation—while deferring lower‑risk fixes. The directive also requires agencies to verify whether an attacker has already compromised a system before applying a patch.

"CISA encourages all organizations, not just federal agencies, to adopt a risk‑based vulnerability management approach and to treat KEV catalog items as top‑priority patching targets," the agency noted.

Next Steps for Defenders

  • Audit your environment for the seven CVEs and apply patches immediately.
  • Check for signs of compromise if the vulnerability has already been exploited.
  • If you spot an actively exploited flaw not yet in the KEV catalog, submit it via CISA’s KEV Nomination Form—just provide a CVE ID, proof of exploitation, and mitigation guidance.

By staying ahead of these newly cataloged threats, security teams can close critical gaps before adversaries exploit them further.

CISA KEV Vulnerability Management CVE Patch Management

← All news