Threat Brief — 2026-09-03 — Seven CVEs hit CISA KEV
CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog in a single batch, spanning network appliances, a PBX platform, a repository manager, an AI gateway, a workflow engine, and an ASGI framework. Three of these — SonicWall SMA1000, Sangoma Switchvox, and JFrog Artifactory — were already under active exploitation reporting from yesterday; their KEV listing confirms the threat is real and remediation deadlines now apply. Four are newly surfaced today with no prior public reporting.
Top items
- CISA KEV: SonicWall SMA1000 OS command injection (CVE-2026-83549KEV) and SSRF (CVE-2026-83548KEV) — Both SonicWall SMA1000 flaws first reported as actively exploited zero-days on 2026-09-02 by BleepingComputer have now been formally added to CISA's KEV catalog. CVE-2026-83549KEV allows authenticated admin-level OS command injection; CVE-2026-83548KEV is an unauthenticated SSRF exposing sensitive data. Both are known-exploited in the wild. (src: CISA KEV)
- CISA KEV: Sangoma Switchvox SQL injection (CVE-2026-9586KEV) — First reported 2026-09-02 by The Hacker News as an unauthenticated remote shell exploit, this SQL injection flaw in Sangoma Switchvox PBX is now confirmed KEV-listed. An unauthenticated attacker can execute arbitrary SQL against the backend PostgreSQL database. Known-exploited in the wild. (src: CISA KEV)
- CISA KEV: JFrog Artifactory improper authentication (CVE-2026-82329KEV) — First reported 2026-09-01 by The Hacker News as an exploited unauthenticated admin-privilege flaw, this vulnerability is now KEV-listed. Under default configuration an unauthenticated network-adjacent attacker can obtain administrative access. Known-exploited in the wild. (src: CISA KEV)
- CISA KEV: Kestra OSS OS command injection (CVE-2026-49869KEV) — Kestra OSS, an open-source workflow orchestration platform, contains an unauthenticated remote command injection vulnerability allowing arbitrary workflow creation and execution without credentials. Newly KEV-listed; known-exploited in the wild. (src: CISA KEV)
- CISA KEV: Kludex Starlette HTTP request/response smuggling (CVE-2026-48710KEV) — The Starlette ASGI framework contains a request/response smuggling vulnerability allowing path injection into the host header. This is a supply-chain-adjacent risk given Starlette's broad use in Python web stacks. Newly KEV-listed; known-exploited in the wild. (src: CISA KEV)
- CISA KEV: BerriAI LiteLLM improper authentication (CVE-2026-59822KEV) — LiteLLM's MCP Streamable HTTP endpoint allows an unauthenticated attacker to establish an authenticated MCP session, bypassing access controls on an AI model gateway. Newly KEV-listed; known-exploited in the wild. (src: CISA KEV)
- AI vulnerability outlook — surge may be manageable — Dark Reporting covers new research suggesting the expected wave of AI-related vulnerabilities, while significant, may be tractable for security teams with the right prioritisation strategies. The evidence is a single analytical article; no new CVE data is introduced. (src: Dark Reading)
Themes
Unauthenticated access dominates the KEV batch. Five of the seven CVEs allow exploitation without any credentials — SSRF, SQL injection, command injection, and two authentication-bypass flaws. The pattern reinforces that perimeter-facing services with default configurations remain the highest-priority attack surface.
AI/ML infrastructure is now a KEV target. The inclusion of BerriAI LiteLLM (an LLM proxy/gateway) and Kestra OSS (workflow orchestration used in data/AI pipelines) marks the first appearance of AI-adjacent infrastructure in the exploited-in-wild catalog, signalling active threat actor interest in these toolchains.
