VMTech
Discuss a project

CISA Lists Seven Actively Exploited Flaws, Including AI Infrastructure Bugs

CISA Lists Seven Actively Exploited Flaws, Including AI Infrastructure Bugs

Seven vulnerabilities enter CISA’s exploited catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of active attacker use. The additions include two CVSS 10.0 issues: CVE-2026-83548, a server-side request forgery flaw in SonicWall SMA 1000 Appliances, and CVE-2026-49869, an operating-system command injection flaw in Kestra OSS.

The other entries are CVE-2026-83549 in SonicWall SMA 1000, CVE-2026-9586 in Sangoma Switchvox, CVE-2026-82329 in JFrog Artifactory, CVE-2026-48710 in Kludex Starlette, and CVE-2026-59822 in Berri LiteLLM’s Model Context Protocol Streamable HTTP endpoint. SonicWall said it investigated a case indicating active exploitation of its two flaws.

Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies are recommended to remediate all of the listed issues except the Starlette and LiteLLM flaws by September 5, 2026. The deadline for CVE-2026-48710 and CVE-2026-59822 is September 16, 2026.

Attack activity ranges from access bypass to cryptomining

CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox that can execute arbitrary SQL statements against the backend PostgreSQL database through one crafted request. Horizon3.ai and watchTowr reported that unknown actors used this issue and CVE-2026-82329, an Artifactory improper-authentication flaw, to deploy reverse shells and mint administrative tokens for further enumeration of users, groups, credential sets and federated access topologies.

Kestra’s CVE-2026-49869 permits an unauthenticated remote attacker to create and execute arbitrary workflows. Microsoft said a threat actor likely exploited it in late June 2026 to establish a reverse shell, inspect a Docker container environment, evade defenses, deploy a cryptocurrency miner and collect data. Microsoft described four impact paths: workflow-engine shell execution, container-environment exposure through Docker socket access, host resource hijacking through mining, and follow-on collection through workflow tasks.

Microsoft also said a later curl-pipe-shell event encoded collected output and stored it through Kestra’s key-value interface, reducing dependence on standalone file artifacts. That detail is relevant to incident investigations because collection and storage may occur through the affected platform’s own functions.

LiteLLM gateways and AI workloads draw attacker interest

The Starlette issue can enable path injection into a host component and authentication bypass where authentication relies on the reconstructed URL path. Horizon3.ai reported in June that CVE-2026-48710 could be chained with CVE-2026-42271 in LiteLLM to bypass authentication and achieve remote code execution. CISA added CVE-2026-42271 to KEV at about the same time, while Wiz linked active exploitation of the chain to Qilin, also known as Agenda, ransomware activity.

Wiz also observed attempts against its honeypots involving CVE-2026-59822, which can allow an unauthenticated party to establish an authenticated MCP session with an arbitrary Bearer token. Microsoft reported that attackers used the LiteLLM chain to deliver an XMRig miner, fingerprint hosts and terminate competing mining processes before accessing LiteLLM-backed PostgreSQL data. The targeted tables included LiteLLM_ProxyModelTable and LiteLLM_VerificationToken, which can contain model configuration, upstream provider key material, provider endpoints and proxy-issued virtual keys.

Microsoft and Wiz said AI infrastructure including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, Ollama, Marimo and MCP servers is being targeted for API keys, backend access, persistence, prompt-injection opportunities and cryptomining. For businesses, the practical response is to treat exposed AI gateways, workflow engines and supporting databases as high-priority control-plane assets: apply the relevant patches by the published deadlines, investigate signs of shells or miner deployment, and rotate keys or tokens that may have been accessible.

#cybersecurity#vulnerability#threatintel#aigateway
Open analytics
On the site 1 views
min read 5 03.09.2026
Instagram

CISA Lists Seven Actively Exploited Flaws, Including AI Infrastructure Bugs

Open the post on Instagram ↗