This month: 7 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-49869
Kestra · Kestra OSS
Kestra OSS OS Command Injection Vulnerability
Detected Sep 2 · 3-day patch deadline
CVE-2026-82329
JFrog · Artifactory
JFrog Artifactory Improper Authentication Vulnerability
Detected Sep 2 · 3-day patch deadline
CVE-2026-83548
SonicWall · SMA1000 Appliances
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Detected Sep 2 · 3-day patch deadline

KEV Intelligence Brief — September 3, 2026

Issued: Thursday, September 3, 2026 | Entries Covered: 8 CVEs added 2026-08-28 through 2026-09-02 | Governing Directive: CISA BOD 26-04

Deadline Watch: Unauthenticated Access Across Critical Infrastructure and DevOps Tooling

Four of this batch's eight entries carry a September 5 patch deadline — meaning federal agencies and covered contractors have roughly 48 hours remaining as of this writing. The urgency here is not bureaucratic. Each of these vulnerabilities allows unauthenticated remote attackers to seize meaningful control over production systems with little or no precondition.

JFrog Artifactory (CVE-2026-82329) is the headline entry for DevOps environments. Under default configuration, an unauthenticated network-adjacent attacker can obtain administrative privileges over Artifactory — the artifact repository that sits at the center of most enterprise software supply chains. Any organization using Artifactory to serve signed packages, container images, or build dependencies should treat this as a supply-chain integrity event, not just a patch task. Until the fix is applied, isolate Artifactory from public internet exposure, rotate all service account tokens and API keys, and audit recent artifact publish events for unauthorized writes. Default configurations are rarely hardened in CI/CD deployments; assume exposure.

SonicWall SMA1000 appliances contribute two entries. CVE-2026-83548 is a server-side request forgery that enables unauthenticated access to sensitive internal functionality — a classic pivot point for lateral movement into protected network segments. CVE-2026-83549 layers an OS command injection vulnerability on top, exploitable by an authenticated administrator for full remote code execution. The practical attack chain is straightforward: exploit the SSRF to interact with internal services or harvest credentials, then leverage those credentials for the RCE. SonicWall edge appliances have been persistent targets for ransomware affiliates and state-sponsored actors; any internet-facing SMA1000 that cannot be patched by September 5 should be taken offline or placed behind explicit allowlist access controls pending remediation.

Sangoma Switchvox (CVE-2026-9586) closes this deadline cluster with a SQL injection vulnerability that requires no authentication and only a single crafted HTTP request to execute arbitrary SQL commands — including remote code execution — against the backend PostgreSQL database. Switchvox is widely deployed in SMB and mid-market telephony environments, often with minimal network segmentation. Organizations should immediately block external access to Switchvox administrative interfaces and treat any internet-exposed instance as potentially compromised pending forensic review, consistent with CISA's Forensics Triage Requirements under BOD 26-04.

Developer Infrastructure and AI Tooling: A Widening Attack Surface

Three vulnerabilities in this batch target the growing ecosystem of developer platforms and AI infrastructure tooling — environments that are frequently under-scrutinized relative to their access to sensitive credentials, source code, and model endpoints.

Kestra OSS (CVE-2026-49869) is perhaps the most operationally dangerous entry in terms of sheer accessibility. An unauthenticated remote attacker can create and execute arbitrary workflows through an OS command injection flaw — effectively handing an attacker a remote code execution engine with no authentication barrier. Kestra is increasingly used in data pipeline and ML orchestration contexts where it has access to cloud credentials, database connections, and inter-service APIs. Patch deadline is September 5. Organizations should immediately disable external access to the Kestra API, audit workflow execution logs for unauthorized runs, and rotate any secrets the orchestrator has access to.

BerriAI LiteLLM (CVE-2026-59822) exposes the MCP Streamable HTTP endpoint to authentication bypass: an attacker can present an arbitrary Bearer token and establish a fully authenticated MCP session. As LiteLLM serves as a proxy and routing layer for LLM API calls, successful exploitation could allow an attacker to exfiltrate API keys for downstream model providers, redirect inference traffic, or abuse metered API quotas at scale. The September 16 deadline provides slightly more runway, but organizations running LiteLLM with internet-accessible endpoints should rotate all LLM provider API keys immediately and restrict MCP endpoint access to known IP ranges.

Kludex Starlette (CVE-2026-48710) rounds out this grouping with an HTTP request/response smuggling vulnerability that enables path injection into the host component of reconstructed URLs, with a primary impact of authentication bypass. CISA explicitly notes this vulnerability can be chained with CVE-2026-42271 — a pairing that likely enables more reliable exploitation. Starlette underpins FastAPI and a significant portion of Python-based microservice infrastructure. Development and staging environments are frequently overlooked in patch cycles; ensure coverage extends beyond production. Deadline is September 16.

Persistent Platform Risk: PaperCut Under Active Exploitation

PaperCut NG/MF (CVE-2026-81578), added to the KEV catalog on August 28, carries a September 11 deadline and warrants renewed urgency as the window closes. The missing authentication vulnerability allows unauthenticated remote modification of system configurations — and CISA explicitly flags a chain with CVE-2026-82078, suggesting a two-stage exploit path is already in active use. PaperCut has been a recurring KEV target over the past several years, often abused for initial access in education and healthcare sectors. Organizations should validate that patches are applied across all print management nodes, not just primary servers, and review configuration change logs from the past 30 days for anomalous modifications. Any system that cannot be patched before September 11 should be isolated from internet exposure immediately.

Analyst Note: Seven of the eight entries in this batch involve unauthenticated attack vectors. The collective pattern reflects adversary preference for credential-free exploitation paths — reducing detection opportunity and operational complexity. BOD 26-04 forensic triage requirements apply to all entries above; organizations should not treat patching alone as sufficient closure.

Sources: CISA KEV Catalog · CISA BOD 26-04 · JFrog Artifactory Security Advisory · SonicWall Product Security Advisories · PaperCut Security Bulletins · Sangoma Security Advisories · CISA Forensics Triage Requirements

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — September 3, 2026

FBI Investigates Mass Driver's License Database Breach Advertised on Russian Forum

A threat actor is advertising the sale of digital scans from approximately 153 million driver's licenses on the Russian-language forum Exploit under the service name "Nexus." The actor claims to have continuously exfiltrated data from an undisclosed source, offering scans that include full identity documentation. The FBI has opened an investigation into the breach, though the compromised entity and timeline of the intrusion have not been publicly identified. The scale of the alleged dataset—if accurate—represents one of the largest compilations of government-issued identification documents offered for sale in recent memory, raising significant fraud and identity theft risks.

Justice Department Pursues Attackers Behind X Password-Recovery Campaign

The U.S. Justice Department is working with X to identify individuals behind a password-recovery attack that targeted hundreds of user accounts. The campaign exploited account recovery mechanisms, though specific technical details of the attack vector have not been disclosed. The investigation marks renewed federal attention on social media platform security following escalating incidents targeting authentication and credential reset functions. The scope of compromised accounts and whether sensitive communications or direct messages were accessed remains unclear.

Sources: PCMag UK · Reuters · Infosecurity Magazine

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.helpnetsecurity.comAug 27

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate

The Justice Department and FBI seized domains tied to hacking tools QScan and QTRouter built and run by Chinese state-sponsored group QTFY that target...

https://thehill.comAug 26

NASA, Fed, Senate among Chinese hackers' targets, Justice Department says

The DOJ announced it disrupted a Chinese hacking operation by Nanjing Xinjiuwei Network Technology Company targeting NASA, the Federal Reserve, and ot...

https://finance.yahoo.comAug 26

US Says China-Linked Hackers Targeted NASA, Fed and Senate

The US Justice Department and FBI disrupted online infrastructure allegedly used by Chinese state-sponsored hackers to target American government agen...

https://securityaffairs.comAug 26

FBI seizes China-linked hacking platforms QScan and QTRouter used to target U.S. critical infrastructure

The U.S. Department of Justice and FBI seized two platforms used by a China-linked group to hide cyberattacks and target critical infrastructure since...

https://thenationaldesk.comAug 27

Chinese state-backed hackers breached U.S. agencies' networks for years, DOJ & FBI says

The Justice Department and FBI announced the seizure of multiple domains connected to the Chinese state-sponsored hacking group QTFY that had breached...

https://cybernews.comAug 31

US healthcare giant McKesson breached, ShinyHunters claims 284m patient records

ShinyHunters claimed it breached US healthcare giant McKesson and made a $55,236,150 ransom demand for 284 million patient records.

https://www.breitbart.comAug 27

DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies

The DOJ seized internet domains tied to QTFY hacking platforms QScan and QTRouter that Chinese state-sponsored operatives used to breach the Federal R...

https://www.cnbc.comAug 26

Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents

The Federal Reserve, U.S. Senate, Department of Justice, and NASA were victims of computer intrusion by Chinese state-sponsored hacking group QTFY, ac...


Updated daily