CISA's list that day
2 September 2026
On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Sangoma Switchvox, Kludex Starlette, Kestra OSS and 3 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-83548Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; Metasploit module | 0.09 | ||
| CVE-2026-83549OS Command Injection | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; Metasploit module | 0.11 | ||
| CVE-2026-9586SQL Injection | Sangoma Switchvox | Patch nowForensic triage required by CISA | 0.19 | ||
| CVE-2026-82329Improper Authentication | JFrog Artifactory | Patch nowForensic triage required by CISA | 0.14 | ||
| CVE-2026-49869OS Command Injection | Kestra Kestra OSS | Patch nowForensic triage required by CISA | 0.02 | ||
| CVE-2026-48710HTTP Request/Response Smuggling | Kludex Starlette | Patch soon | 0.07 | ||
| CVE-2026-59822Improper Authentication | BerriAI LiteLLM | Patch soon | 0.01 |