CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and while two are the SonicWall SMA 1000 flaws already under active attack, the other five mark a broader shift in what is now confirmed under exploitation: a SQL injection flaw in Sangoma Switchvox (CVE-2026-9586), an improper-authentication bug in JFrog Artifactory (CVE-2026-82329) that lets unauthenticated attackers reach administrative privileges, an OS command injection flaw in workflow automation platform Kestra OSS (CVE-2026-49869), an HTTP request smuggling issue in the Python framework Starlette (CVE-2026-48710), and an improper-authentication flaw in the LLM gateway tool LiteLLM (CVE-2026-59822).

Federal agencies must remediate the SonicWall, Sangoma and JFrog flaws by September 5 under Binding Operational Directive 26-04; the Starlette and LiteLLM entries carry a September 16 deadline. That gap matters beyond government networks: Artifactory and LiteLLM are not endpoint products, they are build-pipeline and AI-infrastructure components that sit deep inside a development environment, and a compromise there does not stay contained to one application. Microsoft has separately noted that attackers exploiting flaws in this cluster have aimed to steal API keys, gain backend access, maintain persistence and conduct AI-native post-exploitation activity such as blind prompt injection.

The original insight here is what the LiteLLM and Artifactory additions signal about where active exploitation is moving: away from perimeter appliances that get most of the patching attention and into the CI/CD and AI-gateway layer that many security teams still treat as internal, lower-priority infrastructure. A vulnerability scanner tuned to flag internet-facing systems first will keep missing this category until it is already on CISA’s list. Security teams running any of these five products should treat KEV placement itself as the trigger for emergency patching, not wait for a scheduled maintenance window, since CISA add-to-catalog decisions are themselves evidence of confirmed, not theoretical, exploitation.

Related: the SonicWall SMA 1000 pair that anchors this KEV batch and why a high CVSS score alone still does not tell a defender what to patch first.

Source: CISA Known Exploited Vulnerabilities Catalog