CISA Adds Seven Actively Exploited Flaws to KEV Catalog, Including Two SonicWall SMA1000 Bugs and a LiteLLM Vulnerability

CISA Adds Seven Actively Exploited Flaws to KEV Catalog, Including Two SonicWall SMA1000 Bugs and a LiteLLM Vulnerability

CISA Adds Seven Actively Exploited Flaws to KEV Catalog, Including Two SonicWall SMA1000 Bugs and a LiteLLM Vulnerability

The Cybersecurity and Infrastructure Security Agency, or CISA, has added seven vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing confirmed evidence of active exploitation. The affected products span a wide range of enterprise and infrastructure software, including offerings from Sangoma, Starlette, Kestra, LiteLLM, JFrog Artifactory, and SonicWall. The addition reinforces existing obligations for federal civilian executive branch agencies under Binding Operational Directive 26-04, which requires timely remediation of catalog-listed vulnerabilities.

SonicWall SMA1000 Vulnerabilities: CVE-2026-83548 and CVE-2026-83549

Two of the seven newly listed CVEs affect SonicWall's SMA1000 series appliances, tracked as CVE-2026-83548 and CVE-2026-83549. SonicWall has published its own product security notices and PSIRT advisories acknowledging the flaws, and several independent security vendors, including Sophos, Qualys, Rapid7, and Beazley Security, have corroborated reports of active exploitation in the wild. Many observers note that SMA1000 appliances are attractive targets given their role as internet-facing remote access gateways, though full technical exploitation details continue to be refined as vendors and researchers publish additional analysis.

LiteLLM Flaw Highlights Growing Targeting of AI Infrastructure

Among the seven additions, the LiteLLM vulnerability has drawn particular attention as part of a broader pattern in which threat actors appear to be increasingly focused on AI infrastructure components. Secondary reporting points to related activity affecting Kestra, RAGFlow, and MCP servers, suggesting a recurring trend in which AI-adjacent tooling is viewed by attackers as a lucrative and comparatively under-defended target.

Research published by Wiz has linked exploitation of the LiteLLM vulnerability chain to actors associated with the Qilin/Agenda ransomware operation, though such attribution reporting is inherently based on observed indicators and should be treated as an evolving assessment rather than a settled conclusion. Separately, Microsoft has reported a case in which a related flaw was exploited in mid-2026 to deploy a reverse shell and cryptocurrency mining payload. A recurring concern among security researchers is that AI infrastructure components, often deployed quickly and with less mature security tooling than traditional enterprise software, may represent a growing and underappreciated attack surface.

Remaining KEV Additions: Sangoma, Starlette, Kestra, and JFrog Artifactory

The remaining vulnerabilities added in this update affect Sangoma, Starlette, Kestra, and JFrog Artifactory products. As with all entries in the KEV Catalog, CISA's inclusion criteria require confirmed evidence of active exploitation rather than theoretical risk. Organizations using any of these products are encouraged to review CISA's catalog entry directly for the specific CVE identifiers, affected versions, and remediation guidance associated with each flaw.

Compliance Requirements Under BOD 26-04

Under Binding Operational Directive 26-04, federal civilian executive branch agencies must remediate vulnerabilities listed in the KEV Catalog within mandated deadlines and check their environments for evidence of prior compromise. CISA maintains the KEV Catalog as a continuously updated, authoritative reference intended to help both federal agencies and the broader security community prioritize patching based on real-world exploitation activity rather than severity scores alone.

What Organizations Should Do Now

Security teams, particularly those operating SonicWall SMA1000 appliances or LiteLLM deployments, are encouraged to assess their exposure promptly and align patching timelines with both vendor advisories and CISA guidance. More broadly, a recurring recommendation among security practitioners is to treat AI infrastructure components with the same rigor applied to traditional internet-facing systems, given the apparent shift in attacker focus. CISA has also noted that it welcomes public nominations of additional vulnerabilities believed to be under active exploitation, a process intended to keep the KEV Catalog responsive to emerging threats.

More Tech articles · CuencaLife home