CISA Adds Seven Actively Exploited Vulnerabilities to KEV Catalog
New entries include SQL injection, HTTP smuggling, and command injection flaws across Switchvox, SonicWall, and other platforms
Key Takeaways
- CISA added seven vulnerabilities to the KEV Catalog on 2026-09-02 based on evidence of active exploitation.
- The flaws affect diverse platforms including Sangoma Switchvox, Kludex Starlette, Kestra OSS, LiteLLM, JFrog Artifactory, and SonicWall SMA1000.
- CVE-2026-83548 and CVE-2026-83549 both target SonicWall SMA1000 appliances, with one involving server-side request forgery and the other OS command injection.
- Binding Operational Directive (BOD) 26-04 mandates rapid remediation for FCEB agencies on publicly exposed assets that grant total control post-exploitation.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


