Skip to content
eastbaycyber

CISA Adds 7 Known Exploited Vulnerabilities to Catalog (September 2, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On September 2, 2026, CISA added 7 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-59822, CVE-2026-48710, CVE-2026-49869, CVE-2026-82329, CVE-2026-9586, CVE-2026-83548, CVE-2026-83549. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI · LiteLLM

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Federal due date
2026-09-16
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex · Starlette

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Federal due date
2026-09-16
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability

Kestra · Kestra OSS

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Federal due date
2026-09-05
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability

JFrog · Artifactory

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Federal due date
2026-09-05
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability

Sangoma · Switchvox

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Federal due date
2026-09-05
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Federal due date
2026-09-05
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · SonicWall KEV history

CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability

SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Federal due date
2026-09-05
Ransomware use
Unknown
Added
2026-09-02

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · SonicWall KEV history

Also added to KEV in September 2026

  • September 25, 2026: CVE-2026-87902, WordPress Core (WordPress Core Remote File Inclusion Vulnerability)
  • September 25, 2026: CVE-2026-67279, MikroTik RouterOS (Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability)
  • September 25, 2026: CVE-2026-65660, Microsoft SharePoint (Microsoft SharePoint Code Injection Vulnerability)
  • September 24, 2026: CVE-2026-71362, Adobe Commerce and Magento (Adobe Commerce and Magento Incorrect Authorization Vulnerability )
  • September 24, 2026: CVE-2026-5430, WSO2 Multiple Products (WSO2 Multiple Products Path Traversal Vulnerability )
  • September 22, 2026: CVE-2026-94127, F5 BIG-IP APM (F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability)
  • September 22, 2026: CVE-2026-93952, Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator Improper Input Validation Vulnerability)
  • September 22, 2026: CVE-2026-93616, Check Point Multiple Products (Check Point Multiple Products Path Traversal Vulnerability)
  • September 22, 2026: CVE-2026-85102, Check Point Multiple Products (Check Point Multiple Products Improper Certificate Validation Vulnerability)
  • September 21, 2026: CVE-2026-7273, Zyxel GS1900 Series Switches (Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability)
  • September 18, 2026: CVE-2026-53266, Linux Kernel (Linux Kernel Out-of-Bounds Write Vulnerability)
  • September 18, 2026: CVE-2025-39964, Linux Kernel (Linux Kernel Race Condition Vulnerability)
  • September 18, 2026: CVE-2025-39682, Linux Kernel (Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability)
  • September 16, 2026: CVE-2026-87886, Acronis Backup (Acronis Backup Incorrect Default Permissions Vulnerability)
  • September 16, 2026: CVE-2026-76460, Cisco Identity Services Engine (Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability)
  • September 16, 2026: CVE-2026-58704, Google Pixel (Google Pixel Improper Authorization Vulnerability)
  • September 14, 2026: CVE-2026-76461, Cisco Secure Email Gateway (Cisco Secure Email Gateway SQL Injection Vulnerability)
  • September 11, 2026: CVE-2026-85706, GitLab Community Edition and Enterprise Edition (GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability)
  • September 11, 2026: CVE-2026-84869, ConnectWise ScreenConnect (ConnectWise ScreenConnect Improper Privilege Management and Missing Authorizatio)
  • September 11, 2026: CVE-2026-42018, JFrog Artifactory (JFrog Artifactory Improper Authentication Vulnerability)
  • September 11, 2026: CVE-2026-42016, JFrog Artifactory (JFrog Artifactory Incorrect Authorization Vulnerability)
  • September 10, 2026: CVE-2026-86060, MikroTik RouterOS (MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vu)
  • September 10, 2026: CVE-2026-67277, MikroTik RouterOS (MikroTik RouterOS Missing Authentication for Critical Function Vulnerability)
  • September 9, 2026: CVE-2026-87491, Google Chromium V8 (Google Chromium V8 Out of Bounds Write Vulnerability)
  • September 9, 2026: CVE-2026-20079, Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco Firewall Management Center Authentication Bypass Using an Alternate Path o)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.