TL;DR
Federal officials warned organizations about seven newly abused security flaws. The agency confirmed that threat actors actively exploit these CISA KEV vulnerabilities across enterprise networks. Consequently, system administrators must apply vendor patches immediately to stop intrusions.
- Total: 7 CVEs
- Severity: 4 Critical · 2 High · 1 Medium
- Actively exploited: 7 (zero-day / KEV)
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-49869
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-49869 | 10 | CWE-78 | — | Exploited |
| CVE-2026-83548 | 10 | CWE-441 | — | Exploited |
| CVE-2026-82329 | 9.8 | CWE-287 | 7.111.21, 7.117.28, 7.125.20 (+3) | Exploited |
| CVE-2026-9586 | 9.3 | Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB | 8.4.0.2 | Exploited |
| CVE-2026-59822 | 8.8 | MCP Authentication Bypass via OAuth2 Passthrough Fallback | — | Exploited |
| CVE-2026-83549 | 7.8 | CWE-78 | — | Exploited |
| CVE-2026-48710 | 6.5 | CWE-444 | — | Exploited |
Why It Matters
Threat actors frequently target public-facing network appliances and developer tools. According to federal warnings, “These types of vulnerabilities are a frequent attack vector for malicious cyber actors.” Compromising these systems allows attackers to steal corporate data and deploy ransomware. Furthermore, two of the reported flaws carry a maximum CVSS score of 10.0. Industry estimates indicate that thousands of organizations deploy these impacted systems worldwide. Active exploitation is already occurring in the wild. Therefore, security teams must prioritize these remediations.
How the Attack Works
Adversaries exploit different weaknesses across the affected products. In Kestra OSS (CVE-2026-49869), the platform uses a loose suffix check on API paths. Attackers append this string to bypass authentication and execute code as root. Meanwhile, SonicWall SMA1000 appliances suffer from an alternate access path flaw (CVE-2026-83548). Attackers use this issue to reach sensitive features without prior authentication. Additionally, Sangoma Switchvox (CVE-2026-9586) concatenates phone parameters directly into SQL queries without sanitization. An attacker sends a single request to execute database commands. Finally, Starlette and LiteLLM permit request smuggling and authentication bypasses.
Affected Versions
These flaws affect Sangoma Switchvox SMB Edition 8.3 and Starlette releases prior to 1.0.1. Kestra OSS versions before 1.0.45 and LiteLLM versions before 1.84.0 are also vulnerable. Additionally, JFrog Artifactory and SonicWall SMA1000 appliances harbor active flaws. CISA confirmed that threat actors currently exploit all seven weaknesses in live attacks.
Patch or Mitigation Steps
Administrators must deploy official security updates immediately to secure their environments. Upgrade Starlette to version 1.0.1 and Kestra to 1.0.45 or 1.3.21. Update LiteLLM to 1.84.0 and patch SonicWall appliances promptly. Isolating administrative interfaces behind private firewalls also mitigates exposure. Applying vendor patches resolves these dangerous CISA KEV vulnerabilities.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!