Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
Quick answers
What is CVE-2026-49869?
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
How severe is CVE-2026-49869?
critical
Is CVE-2026-49869 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-49869 be mitigated?
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
Organizations should apply vendor-supplied patches immediately for all seven CVEs. Priority should be given to publicly exposed assets, particularly those within Federal Civilian Executive Branch agencies per BOD 26-04. Systems granting total control post-exploitation should be remediated first. Verify patch availability with respective vendors (Sangoma, Kludex, Kestra, BerriAI/LiteLLM, JFrog, SonicWall) and monitor for updates if patches are not yet released.
The Cybersecurity and Infrastructure Security Agency (CISA) has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The additions span multiple vendors and technologies, including Sangoma Switchvox, Kludex Starlette, Kestra OSS, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. CISA emphasized that these flaws represent frequent attack vectors for malicious actors targeting federal and critical infrastructure systems.