Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["incident", "cisa", "kev", "catalog", "vulnerabilities"] ยท confidence: high ยท severity: medium ยท affected_sectors: ["Government", "Technology", "All"] ยท au_impact: true

CISA Adds Seven Vulnerabilities to Known Exploited Catalog

Summary

CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 2 September: BerriAI LiteLLM improper authentication (CVE-2026-59822), Kludex Starlette HTTP request/response smuggling (CVE-2026-48710), Kestra OSS OS command injection (CVE-2026-49869), the actively exploited JFrog Artifactory authentication bypass (CVE-2026-82329), Sangoma Switchvox SQL injection (CVE-2026-9586) and the two SonicWall SMA1000 command-injection flaws (CVE-2026-83548 / CVE-2026-83549). Federal agencies face binding operational directives to patch, and the catalog is the authoritative source for which flaws are confirmed in the wild; the KEV list is also a direct reference for Australian defenders prioritising application-control and patching measures under the ASD Essential Eight.