This day 02:01 06:01 10:01 14:02 18:03 22:04
⚠ exploit status: CVE-2026-48710 · KEV CVE-2026-49869 · KEV CVE-2026-59822 · KEV CVE-2026-82329 · KEV CVE-2026-83548 · KEV CVE-2026-83549 · KEV CVE-2026-9586 · KEV
High  2026-09-03 02:01Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-09-03 — Seven CVEs hit CISA KEV

CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog in a single batch, spanning network appliances, a PBX platform, a repository manager, an AI gateway, a workflow engine, and an ASGI framework. Three of these — SonicWall SMA1000, Sangoma Switchvox, and JFrog Artifactory — were already under active exploitation reporting from yesterday; their KEV listing confirms the threat is real and remediation deadlines now apply. Four are newly surfaced today with no prior public reporting.

Top items

Themes

Unauthenticated access dominates the KEV batch. Five of the seven CVEs allow exploitation without any credentials — SSRF, SQL injection, command injection, and two authentication-bypass flaws. The pattern reinforces that perimeter-facing services with default configurations remain the highest-priority attack surface.

AI/ML infrastructure is now a KEV target. The inclusion of BerriAI LiteLLM (an LLM proxy/gateway) and Kestra OSS (workflow orchestration used in data/AI pipelines) marks the first appearance of AI-adjacent infrastructure in the exploited-in-wild catalog, signalling active threat actor interest in these toolchains.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db