CISA Adds Seven New Actively Exploited Vulnerabilities to KEV Catalog
The Cybersecurity and Infrastructure Security Agency (**CISA**) has updated its **Known Exploited Vulnerabilities (KEV) Catalog** with seven new entries. These vulnerabilities are confirmed to be under active exploitation, posing significant risks across various software and appliances. Organizations are strongly urged to prioritize their immediate remediation.
In its ongoing effort to bolster cybersecurity defenses, **CISA** has issued a critical update to its **Known Exploited Vulnerabilities (KEV) Catalog**, adding seven new vulnerabilities that have been observed in active attacks. This addition underscores the urgent need for IT security professionals to patch and mitigate these high-risk flaws.
### Newly Added Vulnerabilities
The seven vulnerabilities recently added to the **KEV Catalog** include a range of critical issues:
* **CVE-2026-9586**: **Sangoma Switchvox** SQL Injection Vulnerability
* **CVE-2026-48710**: **Kludex Starlette** HTTP Request/Response Smuggling Vulnerability
* **CVE-2026-49869**: **Kestra OSS** OS Command Injection Vulnerability
* **CVE-2026-59822**: **BerriAI LiteLLM** Improper Authentication Vulnerability
* **CVE-2026-82329**: **JFrog Artifactory** Improper Authentication Vulnerability
* **CVE-2026-83548**: **SonicWall SMA1000 Appliances** Server-Side Request Forgery Vulnerability
* **CVE-2026-83549**: **SonicWall SMA1000 Appliances** OS Command Injection Vulnerability
These types of vulnerabilities are frequently targeted by malicious actors and can lead to severe compromises, including full system control, data exfiltration, and service disruption.
### CISA's Mandate and Recommendations
**CISA's Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk** mandates that Federal Civilian Executive Branch (**FCEB**) agencies rapidly remediate vulnerabilities listed in the **KEV Catalog**, especially those on publicly exposed assets that could grant total control post-exploitation. The directive also emphasizes the importance of checking for prior compromise before applying patches.
While **BOD 26-04** specifically applies to **FCEB** agencies, **CISA** strongly encourages all organizations, regardless of sector, to adopt a risk-based vulnerability management strategy. Prioritizing the remediation of **KEV Catalog** vulnerabilities is a critical step in reducing an organization's attack surface and overall cyber risk.
### Contributing to the KEV Catalog
**CISA** actively solicits contributions to the **KEV Catalog**. If an organization identifies an actively exploited vulnerability not currently listed, they are encouraged to submit it via **CISA's KEV Nomination Form**. Submissions must include a **CVE** ID, verifiable evidence of exploitation, and clear mitigation guidance.