๐ต๏ธ RESEARCH & DEEP DIVES
-
CISA Adds Seven Actively Exploited Flaws to KEV, Including SonicWall, Sangoma, JFrog, and LiteLLM Bugs
CISA added seven actively exploited vulnerabilities to its KEV catalog as attackers deploy reverse shells and crypto miners.- Applies to federal agencies and users of SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM.
- Added flaws: CVE-2026-83548 (SSRF, CVSS 10.0) and CVE-2026-83549 (post-auth OS command injection, CVSS 7.8) in SonicWall SMA 1000; CVE-2026-9586 (SQL injection, CVSS 9.3) in Sangoma Switchvox; CVE-2026-82329 (improper authentication, CVSS 9.8) in JFrog Artifactory.
- Also added: CVE-2026-48710 (HTTP request/response smuggling, CVSS 6.5) in Kludex Starlette; CVE-2026-49869 (OS command injection, CVSS 10.0) in Kestra OSS; CVE-2026-59822 (improper authentication, CVSS 8.8) in Berri LiteLLM's MCP Streamable HTTP endpoint.
- Attackers weaponized CVE-2026-9586 and CVE-2026-82329 to deploy reverse shells and mint admin tokens for enumerating users, groups, credential sets, and federated access.
- A threat actor exploited CVE-2026-49869 in late June 2026 to gain a reverse shell, discover Docker containers, evade defenses, deploy a crypto miner, and harvest data via Kestra's key-value interface.
- Attackers chain CVE-2026-48710 with LiteLLM flaw CVE-2026-42271 to bypass authentication and achieve RCE, deliver an XMRig miner via ELF binary, and steal provider keys from LiteLLM PostgreSQL tables; Qilin ransomware actors linked to the chain.
- FCEB agencies must patch all flaws except CVE-2026-48710 and CVE-2026-59822 by September 5, 2026, and the Starlette and LiteLLM bugs by September 16, 2026.
๐ Source: cisa.gov ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon โ The Hacker News
-
CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks โ Cyber Security News
-
Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability โ Cyber Security News
-
MECCHA CHAMELEON can't hide from the RCE โ aikido.dev (discovered)