CISA's list that day

2 September 2026

On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Sangoma Switchvox, Kludex Starlette, Kestra OSS and 3 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-83548Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.09
CVE-2026-83549OS Command InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.11
CVE-2026-9586SQL InjectionSangoma SwitchvoxPatch nowForensic triage required by CISA0.19
CVE-2026-82329Improper AuthenticationJFrog ArtifactoryPatch nowForensic triage required by CISA0.14
CVE-2026-49869OS Command InjectionKestra Kestra OSSPatch nowForensic triage required by CISA0.02
CVE-2026-48710HTTP Request/Response SmugglingKludex StarlettePatch soon0.07
CVE-2026-59822Improper AuthenticationBerriAI LiteLLMPatch soon0.01