CISA Adds Five AI and Workflow Tool Flaws to KEV Catalog in September 2026
CISA expanded its Known Exploited Vulnerabilities catalog in early September 2026 with five newly confirmed flaws, three of which targeted AI and workflow platforms including BerriAI LiteLLM, the Kestra orchestrator, and Starlette. Adobe Commerce and N-able N-central were added shortly after on September 8 and 9, both with evidence of active exploitation. A key concern across these platforms is that they store credentials for other systems, meaning attackers can harvest secrets even after a patch is applied. Security guidance recommends a strict response order: isolate and patch first, remove any persistent backdoors, then rotate all stored and adjacent credentials. Reviewing provider billing logs and API usage dashboards is also advised, as stolen model API keys generate spending that can surface before internal alerts trigger.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in