Our Blog

Cybersecurity SOC dashboard comparing CVSS vulnerability severity with EPSS and CISA KEV exploitation signals, highlighting flawed vulnerability prioritisation models

Weekly CISA KEV Updates: 7 September 2026 - Ten New Known Exploited Vulnerabilities Added

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

 

 

Subscribe to get these articles directly to your inbox when published

 

 

This Week's KEV Additions

CVE ID Vendor / Product CVSS Date Added CISA Due Date Exploitation Type EPSS Score Reachability
CVE-2026-85046 Google Chromium V8 8.8 (High) 2026-09-04 2026-09-18 Type Confusion 1.3% Remote (Network)
CVE-2026-59822 BerriAI LiteLLM 8.8 (High) 2026-09-02 2026-09-16 Improper Authentication 0.9% Remote (Network)
CVE-2026-48710 Kludex Starlette Moderate 2026-09-02 2026-09-16 Request/Response Smuggling 36.3% Remote (Network)
CVE-2026-49869 Kestra OSS 10.0 (Critical) 2026-09-02 2026-09-05 OS Command Injection 1.9% Remote (Network)
CVE-2026-82329 JFrog Artifactory 9.8 (Critical) 2026-09-02 2026-09-05 Improper Authentication 7.7% Network
CVE-2026-9586 Sangoma Switchvox 9.3 (Critical) 2026-09-02 2026-09-05 SQL Injection 11.8% Remote (Network)
CVE-2026-83548 SonicWall SMA1000 10.0 (Critical) 2026-09-02 2026-09-05 Server-Side Request Forgery 4.7% Remote (Network)
CVE-2026-83549 SonicWall SMA1000 7.8 (High) 2026-09-02 2026-09-05 OS Command Injection 8.5% Remote (Authenticated)
CVE-2026-82078 PaperCut NG/MF 9.4 (Critical) 2026-08-31 2026-09-14 Unsafe Reflection / Dynamic Class-Loading 1.7% Network
CVE-2026-81578 PaperCut NG/MF 8.8 (High) 2026-08-31 2026-09-14 Missing Authentication for Critical Function 1.6% Network

Note: EPSS scores are as published by FIRST.org at time of writing and are not updated after publication; scores change daily.

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

Analysis

 

CVE-2026-85046 — Google Chromium V8

  • What it is: A type confusion vulnerability in Google Chromium's V8 JavaScript and WebAssembly engine that allows remote attackers to execute arbitrary code inside the sandbox via a crafted HTML page.

  • Affected versions: Google Chromium versions prior to the security patch release.

  • Exploitation status: Actively exploited in the wild as a zero-day.

  • Patch available: Yes, updated browser versions released by Google.

  • CISA due date: 2026-09-18

  • Operational risk: Compromise of endpoint browsers enabling arbitrary code execution within user contexts, risking corporate data exposure and client-side attacks.

 

CVE-2026-59822 — BerriAI LiteLLM

  • What it is: An improper authentication vulnerability in the MCP Streamable HTTP endpoint of BerriAI LiteLLM allowing unauthenticated attackers to establish valid authenticated MCP sessions.

  • Affected versions: BerriAI LiteLLM versions prior to 1.84.0.

  • Exploitation status: Confirmed exploitation in the wild.

  • Patch available: Yes, version 1.84.0 and later.

  • CISA due date: 2026-09-16

  • Operational risk: Unauthorized access to AI gateway proxies and backend models, exposing sensitive API credentials and corporate LLM tooling data.

 

CVE-2026-48710 — Kludex Starlette

  • What it is: A request/response smuggling vulnerability in Starlette allowing path injection via host headers, resulting in security controls and authentication bypasses.

  • Affected versions: Starlette versions 0.8.3 through 1.0.0.

  • Exploitation status: Actively targeted in the wild.

  • Patch available: Yes, version 1.0.1 and later.

  • CISA due date: 2026-09-16

  • Operational risk: Circumvention of path-based authorization middleware across Python ASGI applications, FastAPI services, and AI backends.

 

CVE-2026-49869 — Kestra OSS

  • What it is: An OS command injection vulnerability in Kestra OSS enabling unauthenticated remote attackers to create and execute arbitrary workflows without credentials.

  • Affected versions: Kestra OSS versions prior to the official security fix.

  • Exploitation status: Actively exploited leading to reverse shells and crypto-miner deployments.

  • Patch available: Yes, check vendor advisory for updated releases.

  • CISA due date: 2026-09-05

  • Operational risk: Complete container compromise, infrastructure takeovers, data exfiltration from key-value stores, and resource hijacking.

 

CVE-2026-82329 — JFrog Artifactory

  • What it is: An improper authentication vulnerability in JFrog Artifactory (Access component) allowing unauthenticated network attackers to obtain administrative privileges under default configuration.

  • Affected versions: Multiple self-hosted branches including versions prior to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.

  • Exploitation status: Actively exploited with automated scanning and attacker token minting observed.

  • Patch available: Yes, branch-specific patched releases provided by JFrog.

  • CISA due date: 2026-09-05

  • Operational risk: Full software supply chain compromise, repository tampering, configuration exposure, and theft of federation cluster secrets.

 

CVE-2026-9586 — Sangoma Switchvox

  • What it is: An unauthenticated SQL injection vulnerability in Sangoma Switchvox allowing remote attackers to execute arbitrary SQL commands against the backend PostgreSQL database.

  • Affected versions: Sangoma Switchvox SMB Edition 8.3 (build 104997) and prior vulnerable builds.

  • Exploitation status: Actively exploited in the wild.

  • Patch available: Yes, vendor patches available.

  • CISA due date: 2026-09-05

  • Operational risk: Database manipulation, credential theft, and escalation to remote code execution on telephony and unified communications infrastructure.

 

CVE-2026-83548 — SonicWall SMA1000

  • What it is: A pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface due to unintended alternate access paths.

  • Affected versions: SMA1000 versions 12.4.3-03453, 12.5.0-02835 and older versions.

  • Exploitation status: Actively exploited in the wild, frequently chained with command injection.

  • Patch available: Yes, platform hotfixes released by SonicWall.

  • CISA due date: 2026-09-05

  • Operational risk: Unauthorized access to internal administrative functions, perimeter security bypass, and potential full gateway compromise.

 

CVE-2026-83549 — SonicWall SMA1000

  • What it is: An OS command injection vulnerability in the Appliance Management Console (AMC) enabling authenticated administrator users to execute arbitrary operating system commands.

  • Affected versions: SMA1000 platform hotfix versions 12.4.3-03453, 12.5.0-02835 and older.

  • Exploitation status: Actively exploited in combination with CVE-2026-83548.

  • Patch available: Yes, platform hotfixes available from SonicWall.

  • CISA due date: 2026-09-05

  • Operational risk: Remote code execution at the root level on VPN appliances, compromising encrypted perimeter tunnels and enterprise access control.

 

CVE-2026-82078 — PaperCut NG/MF

  • What it is: An unsafe dynamic class-loading vulnerability within database connection utilities allowing execution of arbitrary Java bytecode on the classpath.

  • Affected versions: PaperCut NG/MF versions prior to Emergency Patch Release 2.

  • Exploitation status: Actively exploited in the wild in an attack chain.

  • Patch available: Yes, emergency patches for versions 24, 25, and 26.

  • CISA due date: 2026-09-14

  • Operational risk: Remote code execution under the application server security context, system configuration tampering, and internal network reconnaissance.

 

CVE-2026-81578 — PaperCut NG/MF

  • What it is: A missing authentication / improper access control vulnerability in the web management interface allowing unauthenticated remote modification of system configurations.

  • Affected versions: PaperCut NG and MF versions prior to Emergency Patch Release 2.

  • Exploitation status: Actively exploited in combination with CVE-2026-82078.

  • Patch available: Yes, emergency security patches released by PaperCut.

  • CISA due date: 2026-09-14

  • Operational risk: Unauthorized administrative configuration changes leading directly into pre-authentication remote code execution chains.

 

Exploitation Context

Recent additions to CISA's Known Exploited Vulnerabilities catalog highlight an alarming trend of threat actors aggressively targeting modern application stacks, developer tooling, and perimeter infrastructure. Critical flaws in AI agent frameworks, workflow orchestrators like Kestra, and artifact repositories such as JFrog Artifactory demonstrate that attackers are shifting focus toward software supply chain pipelines and automated backend infrastructure to establish deep persistence and mint administrative privileges.

 

Simultaneously, traditional edge devices and enterprise printing solutions—exemplified by SonicWall SMA1000 appliances and PaperCut servers—continue to face coordinated exploitation chains where authentication bypasses and SSRF bugs are weaponized for remote code execution. Security teams must prioritize rapid patching and strict network segmentation for internet-exposed administrative interfaces to counter these active intrusion campaigns.

 

 

Remediation Priorities

 

Priority CVE ID Recommended Action Timeline
1 CVE-2026-49869 Upgrade Kestra OSS immediately and restrict network access to untrusted entities. Immediate
2 CVE-2026-83548 Apply SonicWall SMA1000 platform hotfixes and verify perimeter gateway logs. Immediate
3 CVE-2026-82329 Upgrade self-hosted JFrog Artifactory to latest patched version and rotate credentials/join keys. Immediate
4 CVE-2026-82078 Apply PaperCut Emergency Patch Release 2 across all primary and secondary print servers. Within 24 hours
5 CVE-2026-9586 Update Sangoma Switchvox to patched builds and audit database logs. Within 24 hours
6 CVE-2026-85046 Deploy updated Google Chrome builds across enterprise endpoints. Within 72 hours
7 CVE-2026-59822 Upgrade BerriAI LiteLLM to v1.84.0 or block external access to /mcp/ endpoints. Within 72 hours
8 CVE-2026-81578 Apply PaperCut emergency patches and restrict management access. Within 72 hours
9 CVE-2026-83549 Apply SonicWall AMC patches alongside CVE-2026-83548 remediation. By CISA due date
10 CVE-2026-48710 Upgrade Starlette to v1.0.1+ or deploy RFC-compliant reverse proxies. By CISA due date

 

 

Detection and Monitoring Guidance

 

  • CVE-2026-85046 (Google):

    • Log Sources: Browser telemetry, Endpoint Detection and Response (EDR) process execution logs.

    • Behavioral Indicators: Unexpected child process spawning from browser renderers or abnormal memory access patterns.

    • Monitoring Gap / Detection Artifacts: Heavily obfuscated web exploit payloads delivered via drive-by downloads.

 

  • CVE-2026-59822 (BerriAI):

    • Log Sources: API gateway access logs, LiteLLM server request logs.

    • Behavioral Indicators: Unauthorized Bearer tokens or fabricated authorization headers hitting /mcp/ endpoints.

    • Monitoring Gap / Detection Artifacts: Fallback authentication handling bypasses standard audit logs unless explicitly tuned.

 

  • CVE-2026-48710 (Kludex):

    • Log Sources: ASGI web server access logs, reverse proxy telemetry (Nginx/Apache).

    • Behavioral Indicators: Malformed HTTP Host headers containing injected path characters.

    • Monitoring Gap / Detection Artifacts: Standard application middleware logs may record reconstructed URLs rather than raw scope paths.

 

  • CVE-2026-49869 (Kestra):

    • Log Sources: Kestra workflow execution logs, container runtime logs, system audit logs.

    • Behavioral Indicators: Unauthenticated workflow creation, unexpected outbound connections, high CPU usage from crypto-miners.

    • Monitoring Gap / Detection Artifacts: Lack of strict authentication enforcement on API endpoints.

 

  • CVE-2026-82329 (JFrog):

    • Log Sources: Artifactory access logs, JFrog Access audit logs, system event logs.

    • Behavioral Indicators: Unrecognized administrator token issuance events, mass enumeration queries for users and repositories.

    • Monitoring Gap / Detection Artifacts: Minted admin tokens appear indistinguishable from legitimate administrative activity.

 

  • CVE-2026-9586 (Sangoma):

    • Log Sources: Switchvox web server logs, PostgreSQL database query logs.

    • Behavioral Indicators: Malformed XML payloads targeting the /pa endpoint containing SQL injection syntax.

    • Monitoring Gap / Detection Artifacts: Encrypted traffic or obfuscated inputs hiding SQL query structures.

 

  • CVE-2026-83548 (SonicWall):

    • Log Sources: SMA1000 Work Place web access logs, firewall connection telemetry.

    • Behavioral Indicators: Anomalous internal requests originating from the Work Place interface to restricted resources.

    • Monitoring Gap / Detection Artifacts: Unintended alternate access paths bypassing standard perimeter logging.

 

  • CVE-2026-83549 (SonicWall):

    • Log Sources: Appliance Management Console (AMC) administrative logs, system shell logs.

    • Behavioral Indicators: Execution of unexpected shell commands or binary processes from management console daemons.

    • Monitoring Gap / Detection Artifacts: Post-exploitation activity executed under legitimate administrator sessions.

 

  • CVE-2026-82078 (PaperCut):

    • Log Sources: PaperCut server.log files, EDR process logs for pc-app.exe.

    • Behavioral Indicators: Errors such as "No suitable driver found for jdbc" or unexpected .class / .cmd files in server directories.

    • Monitoring Gap / Detection Artifacts: Truncated or deleted server log files following intrusion attempts.

 

  • CVE-2026-81578 (PaperCut):

    • Log Sources: Web management interface access logs, Apache Tapestry request logs.

    • Behavioral Indicators: Forged URLs invoking sensitive configuration functions (ConfigEditor) without prior session authentication.

    • Monitoring Gap / Detection Artifacts: Requests bypassing permission checks due to framework trust rendering issues.

 

 

Hackerstorm Analysis

This week’s catalog additions underscore a convergence of attacks targeting modern software supply chains and perimeter defenses. The inclusion of critical flaws across AI frameworks (LiteLLM, Starlette, Kestra) and enterprise infrastructure (JFrog Artifactory, SonicWall, PaperCut) illustrates that adversaries are increasingly combining authentication bypasses with native execution mechanisms. Security teams must treat build servers, artifact repositories, and AI orchestration engines as Tier-1 critical assets requiring rigorous isolation and continuous log monitoring.

 

 

What you should do next

Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities.  View all weekly reports here

 

 

 

 

Further Reading

The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.

 

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

 

 

 


About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

 

 

 

 

 

 

 

 

 

 

 

 

 

 


 

Analyst Notes

  • No ransomware attribution was publicly associated with this week's KEV additions at the time of publication.
  • No confirmed threat actor attribution was available beyond CISA's confirmation of active exploitation for the majority of entries.
  • Where vendor advisory details or EPSS values were unavailable at publication time, placeholders were retained pending analyst validation and vendor updates prior to final publication.

 

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy