THREAT SUMMARY
Category: Actively Exploited Vulnerabilities / Enterprise Infrastructure / Application Security
Affected Product(s): Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, SonicWall SMA1000 Appliances
CVE(s): CVE-2026-9586, CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549
Primary Risks: SQL injection, HTTP request/response smuggling, OS command injection, authentication bypass or improper authentication, server-side request forgery, unauthorized system access, remote code or command execution depending on vulnerable component and exploitation path
Threat Status: Active exploitation confirmed by CISA
Affected Environment(s): Publicly exposed enterprise applications, communications infrastructure, development and orchestration platforms, AI application gateways, artifact repositories, and remote-access appliances
Attack Vector(s): Internet-facing services, crafted HTTP traffic, vulnerable authentication mechanisms, command injection paths, server-side request manipulation, and exposed application interfaces
CISA Action: Seven vulnerabilities added to the Known Exploited Vulnerabilities Catalog on September 2, 2026
Required Response: Federal Civilian Executive Branch agencies must apply the risk-based requirements of Binding Operational Directive 26-04, including rapid remediation of high-risk KEV vulnerabilities on publicly exposed assets that grant total control after exploitation. CISA encourages all other organizations to prioritize remediation of KEV Catalog vulnerabilities.
CISA has added seven vulnerabilities affecting six products or projects to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.
The September 2 additions span communications systems, Python web infrastructure, workflow orchestration platforms, AI gateway software, software artifact repositories, and enterprise remote-access appliances.
The affected products are Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances.
Two of the newly listed vulnerabilities affect SonicWall SMA1000 systems, while the remaining five affect separate software platforms.
The additions are significant because inclusion in CISA’s KEV Catalog means the vulnerabilities have moved beyond theoretical exposure or proof-of-concept risk. CISA added the vulnerabilities based on evidence of active exploitation.
That places these flaws in a different operational category from vulnerabilities that are serious on paper but have no confirmed exploitation activity.
Vulnerability Details
CVE-2026-9586 — Sangoma Switchvox SQL Injection Vulnerability
CISA identified CVE-2026-9586 as an actively exploited SQL injection vulnerability affecting Sangoma Switchvox.
SQL injection vulnerabilities occur when an application fails to properly control attacker-supplied input before using it in database operations.
Successful exploitation can potentially allow an attacker to manipulate database queries, extract sensitive information, alter stored data, bypass application controls, or create further access opportunities depending on the affected implementation.
Organizations operating internet-accessible Switchvox systems should treat exposure to this CVE as a priority because CISA has confirmed exploitation rather than listing the flaw solely on severity.
CVE-2026-48710 — Kludex Starlette HTTP Request/Response Smuggling Vulnerability
CVE-2026-48710 affects Kludex Starlette and is classified as an HTTP request/response smuggling vulnerability.
HTTP smuggling vulnerabilities arise when two systems processing the same web traffic interpret request boundaries or message structure differently.
That disagreement can allow malicious traffic to be concealed inside apparently legitimate connections.
Depending on the affected architecture, request smuggling can be used to interfere with application routing, bypass security controls, manipulate sessions, poison caches, reach protected endpoints, or create conditions for follow-on attacks.
Starlette is used as a web application framework, making exposed applications and services built around affected versions especially relevant to defenders reviewing internet-facing infrastructure.
CVE-2026-49869 — Kestra OSS OS Command Injection Vulnerability
CISA added CVE-2026-49869, an OS command injection vulnerability affecting Kestra OSS.
Command injection vulnerabilities are among the most serious classes of application-security flaws because successful exploitation can allow attacker-controlled input to reach operating-system command execution paths.
If exploitation reaches that level, an attacker could potentially execute commands with the privileges assigned to the vulnerable service.
That may expose application data, credentials, connected infrastructure, secrets, workflow information, or other systems accessible from the compromised host.
For orchestration platforms, the operational impact can be broader than a single application because these environments frequently interact with databases, cloud services, internal APIs, automation systems, and deployment infrastructure.
CVE-2026-59822 — BerriAI LiteLLM Improper Authentication Vulnerability
CVE-2026-59822 affects BerriAI LiteLLM and is classified as an improper authentication vulnerability.
Improper authentication flaws can allow attackers to reach functionality or resources that should require legitimate credentials or stronger identity verification.
The risk is especially important for AI gateway or proxy infrastructure because these systems can sit between users, applications, API credentials, and multiple model providers.
A successful authentication bypass could expose protected interfaces, administrative functions, API configuration, usage information, or downstream services depending on the vulnerable deployment.
CISA’s KEV designation confirms attackers are already exploiting the flaw in real environments.
CVE-2026-82329 — JFrog Artifactory Improper Authentication Vulnerability
CISA also added CVE-2026-82329, an improper authentication vulnerability affecting JFrog Artifactory.
Artifact repositories are critical components of software-development and deployment pipelines because they store packages, binaries, build artifacts, dependencies, and other software components.
Unauthorized access to an artifact repository can carry significant operational consequences.
Potential exposure can extend beyond the repository itself if attackers gain access to software packages, deployment artifacts, credentials, tokens, internal metadata, or trusted components later consumed by development and production systems.
Because software supply-chain systems occupy trusted positions inside development environments, defenders should treat active exploitation against Artifactory as a potentially high-impact enterprise risk.
CVE-2026-83548 — SonicWall SMA1000 Server-Side Request Forgery Vulnerability
CVE-2026-83548 affects SonicWall SMA1000 appliances and is classified as a server-side request forgery vulnerability.
Server-side request forgery, commonly called SSRF, allows attackers to manipulate a vulnerable server into making requests on their behalf.
That can expose internal systems or services that are not directly accessible from the public internet.
Depending on the affected architecture, SSRF may allow attackers to probe internal network resources, interact with local services, retrieve cloud metadata, access management interfaces, or create paths toward deeper compromise.
The security implications are amplified when the vulnerable product is a remote-access appliance positioned at the network perimeter.
CVE-2026-83549 — SonicWall SMA1000 OS Command Injection Vulnerability
The second SonicWall vulnerability added to KEV is CVE-2026-83549, an OS command injection flaw affecting SMA1000 appliances.
This vulnerability is particularly important when viewed alongside CVE-2026-83548 because both affect the same appliance family and both are now associated with confirmed exploitation.
Command injection on a perimeter device can create substantial risk if attackers are able to execute operating-system commands on systems positioned between external users and internal enterprise resources.
Compromise of remote-access infrastructure can potentially provide attackers with a strategic foothold from which to steal credentials, inspect configuration data, establish persistence, or move further into an environment.
Organizations running SMA1000 appliances should therefore evaluate both CVEs together rather than treating them as isolated weaknesses.
Operational Impact
The seven vulnerabilities affect technologies positioned at several critical layers of enterprise environments.
- Sangoma Switchvox places voice and communications infrastructure in scope.
- Starlette introduces risk within application and web-service environments.
- Kestra OSS affects workflow and orchestration infrastructure.
- LiteLLM places AI application gateways and model-access infrastructure in scope.
- JFrog Artifactory affects software-development and supply-chain environments.
- SonicWall SMA1000 exposes perimeter and remote-access infrastructure.
- Several vulnerabilities involve authentication bypass or command execution, creating potential paths toward unauthorized system control.
- The presence of both SSRF and command injection vulnerabilities in the same SonicWall product family raises the importance of perimeter review.
- Artifactory compromise could create downstream software-supply-chain concerns if attackers gain access to trusted artifacts or repository controls.
- Compromise of orchestration or AI gateway platforms may expose credentials, tokens, internal APIs, or connected services depending on deployment architecture.
CISA’s confirmation of active exploitation means defenders should not evaluate these CVEs solely through CVSS scores or normal patch cycles.
Observed exploitation should elevate remediation priority.
Federal Response
The September 2 additions fall under Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk.
BOD 26-04 establishes vulnerability-management requirements for Federal Civilian Executive Branch agencies and reinforces the KEV Catalog as a central mechanism for identifying vulnerabilities requiring accelerated remediation.
The directive places particular emphasis on KEV vulnerabilities affecting publicly exposed assets that can grant complete control of the asset after successful exploitation.
It also establishes expectations for determining whether systems may have been compromised before patches or mitigations were applied.
That distinction is critical.
Applying an update removes the vulnerability going forward, but it does not establish whether an attacker already exploited the system before remediation.
For systems exposed during a confirmed exploitation window, federal agencies may need to perform compromise assessment in addition to patching.
KEV
CISA adds vulnerabilities to the Known Exploited Vulnerabilities Catalog when they satisfy defined criteria that include:
- Assignment of a CVE identifier.
- Evidence of exploitation.
- Availability of clear mitigation guidance.
The KEV Catalog is designed to distinguish vulnerabilities attackers are actively using from the much larger population of disclosed software flaws.
The September 2 update contains seven separate vulnerabilities across six vendors or projects, creating a broad remediation requirement rather than a single-product emergency.
Organizations outside the federal government are not legally bound by BOD 26-04, but CISA continues to recommend that private-sector organizations incorporate KEV status into vulnerability-management priorities.
Defensive Guidance
Organizations operating affected products should immediately identify whether vulnerable versions are deployed and determine whether those systems are exposed to the internet.
Priority actions should include:
- Inventory all Sangoma Switchvox, Starlette, Kestra OSS, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 deployments.
- Identify externally accessible systems before reviewing internal-only installations.
- Apply vendor-approved updates or mitigations for all seven KEV entries.
- Review SonicWall SMA1000 systems for exposure to both CVE-2026-83548 and CVE-2026-83549.
- Inspect authentication logs and administrative activity on LiteLLM and Artifactory systems.
- Review web and proxy logs for anomalous HTTP behavior affecting Starlette deployments.
- Examine Kestra systems for unexplained operating-system command execution, process creation, configuration changes, or credential access.
- Review Switchvox systems for unusual database queries, administrative changes, new accounts, or unexplained access patterns.
- Conduct compromise assessment on systems that were publicly exposed before remediation.
- Rotate credentials, tokens, secrets, or API keys if there is evidence an affected system was compromised.
- Review connected systems for lateral movement if command execution or unauthorized administrative access is discovered.
- Preserve relevant logs and forensic evidence before rebuilding compromised systems.
Patching alone should not be considered sufficient where exploitation may have occurred before remediation.
30-Day Outlook
The immediate risk surrounding these seven vulnerabilities is likely to remain elevated because KEV additions frequently increase defender attention and attacker awareness at the same time.
Organizations should expect:
- Continued exploitation attempts against internet-accessible systems that remain unpatched.
- Broader scanning for exposed SonicWall SMA1000 appliances.
- Increased targeting of Artifactory and other software-development infrastructure where attackers can gain access to trusted repositories.
- Attempts to exploit exposed orchestration and AI gateway services for credentials or downstream access.
- Expanded detection signatures and threat-hunting guidance from vendors and security teams as exploitation data develops.
- Greater scrutiny of systems that were exposed before patches became available or before organizations completed remediation.
- Potential follow-on activity where attackers already established persistence before vulnerabilities were addressed.
The most important defensive distinction during this period is between vulnerability remediation and incident response.
An organization that patches a system after exploitation has already occurred may still have an active compromise.
TRJ Verdict
The September 2 KEV update is unusually broad because it spans communications systems, web frameworks, automation platforms, AI infrastructure, software repositories, and perimeter remote-access appliances in a single release.
The strongest warning is not the number of CVEs.
It is the fact that all seven have evidence of active exploitation.
CVE-2026-49869 and CVE-2026-83549 carry the inherent danger associated with OS command injection. CVE-2026-59822 and CVE-2026-82329 raise authentication-control concerns. CVE-2026-83548 places server-side request forgery on a perimeter appliance. CVE-2026-48710 introduces HTTP smuggling risk into web infrastructure, while CVE-2026-9586 creates a database attack path through SQL injection.
Organizations using any affected product should move these vulnerabilities out of routine patch queues and into immediate risk-based remediation and compromise assessment.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



