CISA Adds Seven Known Exploited Vulnerabilities to Catalog

Summary

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively being exploited. These vulnerabilities affect various software and appliances, including Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. The addition of these CVEs reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize remediation of high-risk vulnerabilities.

IFF Assessment

FOE

The article lists newly identified actively exploited vulnerabilities, which represent new risks and attack vectors for defenders.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must be aware of these newly identified, actively exploited vulnerabilities and ensure their systems are patched promptly, especially for publicly exposed assets. The inclusion in CISA's KEV catalog signifies a heightened risk, and organizations should prioritize remediation efforts to mitigate potential attacks.

Read Full Story →