The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven newly exploited security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after multiple flaws were found being used in active cyber campaigns. The latest additions include vulnerabilities affecting SonicWall SMA 1000 Appliances, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. The update follows evidence that threat actors are using these weaknesses to gain unauthorized access, execute remote code, deploy reverse shells, install cryptocurrency miners, and target artificial intelligence infrastructure.
The newly listed vulnerabilities include CVE 2026 83548, a server side request forgery flaw in SonicWall SMA 1000 Appliances with a CVSS score of 10.0 that can allow remote unauthenticated attackers to access sensitive functionality. CISA also added CVE 2026 83549, an operating system command injection flaw in the same product that enables authenticated administrators to execute arbitrary operating system commands. Other additions include CVE 2026 9586, an SQL injection vulnerability in Sangoma Switchvox, CVE 2026 82329 affecting JFrog Artifactory, CVE 2026 48710 impacting Starlette, CVE 2026 49869 in Kestra OSS, and CVE 2026 59822 affecting the LiteLLM Model Context Protocol Streamable HTTP endpoint. According to reports from Horizon3.ai and watchTowr, attackers have already been using the Switchvox and JFrog vulnerabilities to deploy reverse shells and generate administrative tokens for further network discovery, user enumeration, credential collection, and access to federated environments. SonicWall has also confirmed that it investigated a case involving the active exploitation of the two SMA vulnerabilities.
Security researchers have also linked multiple vulnerabilities to attacks targeting AI infrastructure. Earlier research showed that the Starlette vulnerability could be chained with LiteLLM vulnerability CVE 2026 42271 to bypass authentication and achieve remote code execution on vulnerable LiteLLM deployments. That LiteLLM flaw was previously added to the KEV catalog, while cloud security company Wiz reported that threat actors associated with the Qilin ransomware group have actively exploited the vulnerability chain. Wiz also observed attempts to exploit CVE 2026 59822 against its honeypots to probe model enumeration endpoints. Separately, Microsoft disclosed that CVE 2026 49869 in Kestra OSS was likely exploited in late June 2026 to establish reverse shells, inspect Docker container environments, evade security controls, deploy cryptocurrency miners, and collect data. Microsoft further reported that attackers have been compromising LiteLLM gateways by combining CVE 2026 42271 and CVE 2026 48710 to deliver XMRig cryptocurrency miners after identifying system details and removing competing mining processes. The activity also included targeting LiteLLM backed PostgreSQL databases to obtain model configurations, provider credentials, endpoint information, and proxy issued virtual keys while establishing persistence through SSH authorized keys modifications and command and control techniques.
Microsoft and Wiz noted that these campaigns demonstrate the increasing focus on AI infrastructure, including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, Ollama, Marimo, and Model Context Protocol servers, as attackers seek API keys, backend system access, long term persistence, AI focused post exploitation opportunities, and cryptocurrency mining. In a separate campaign, Microsoft said exposed RAGFlow instances are also believed to have been targeted through several vulnerabilities to obtain large language model provider keys and related metadata. According to the company, telemetry across different incidents consistently showed credential collection, persistence mechanisms, and resource monetization despite variations in attack methods. Under Binding Operational Directive 26 04, Federal Civilian Executive Branch agencies have been instructed to apply patches for all newly listed vulnerabilities except CVE 2026 48710 and CVE 2026 59822 by September 5, 2026, while remediation for the Starlette and LiteLLM vulnerabilities has been scheduled for completion by September 16, 2026.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





