CISA Flags Seven Actively Exploited Vulnerabilities Across AI, VoIP, and VPN Products
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added seven critical vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2, 2026, affecting products including LiteLLM, Starlette, Kestra, JFrog Artifactory, Sangoma Switchvox, and SonicWall SMA 1000. The flaws span authentication bypasses, server-side request forgery, SQL injection, and command injection, allowing unauthenticated attackers to execute arbitrary code, gain administrator privileges, or take control of VPN appliances. Federal agencies and affected organizations face a tight remediation deadline of September 5, 2026, for vulnerabilities in Kestra, Artifactory, Switchvox, and SonicWall. Most of the vulnerabilities require no user interaction, making them harder to detect through conventional monitoring. CISA recommends applying vendor-issued patches immediately and restricting external exposure of affected management interfaces.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in