CISA Adds Seven Vulnerabilities to Known Exploited Catalog
Summary
CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 2 September: BerriAI LiteLLM improper authentication (CVE-2026-59822), Kludex Starlette HTTP request/response smuggling (CVE-2026-48710), Kestra OSS OS command injection (CVE-2026-49869), the actively exploited JFrog Artifactory authentication bypass (CVE-2026-82329), Sangoma Switchvox SQL injection (CVE-2026-9586) and the two SonicWall SMA1000 command-injection flaws (CVE-2026-83548 / CVE-2026-83549). Federal agencies face binding operational directives to patch, and the catalog is the authoritative source for which flaws are confirmed in the wild; the KEV list is also a direct reference for Australian defenders prioritising application-control and patching measures under the ASD Essential Eight.