CISA Adds Seven Vulnerabilities to KEV Catalog
CISA adds seven actively exploited vulnerabilities affecting AI infrastructure, Python frameworks, and SonicWall to its KEV catalog, with a September 5, 2026 deadline.

Stock photo for illustration only, not from the actual event
- CISA adds seven actively exploited vulnerabilities to the KEV catalog
- Impacts AI infrastructure, Python web frameworks, VoIP, and VPNs
- Strict remediation deadline set for September 5, 2026, on key products
- Administrators must audit for compromised tokens and child processes
The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding seven security flaws affecting widely used platforms. The newly listed software and services include LiteLLM, Starlette, Kestra, JFrog Artifactory, Sangoma Switchvox, and SonicWall SMA 1000.
Alongside the catalog update, CISA has issued an aggressive remediation timeline. Organizations running Kestra, JFrog Artifactory, Sangoma Switchvox, and SonicWall products must apply the necessary security patches by September 5, 2026, due to the high-privilege management exposure these systems present to enterprise networks.
The newly identified vulnerabilities span a diverse range of critical enterprise technologies, encompassing AI gateways, Python web services, workflow engines, artifact repositories, VoIP systems, and SSL VPNs. Because these environments handle high-privilege management tasks, they represent prime targets for threat actors seeking lateral movement.

Stock photo for illustration only, not from the actual event
The inclusion of AI gateways and modern Python web frameworks in CISA's catalog highlights a critical shift in the threat landscape, where attackers increasingly target emerging technologies that organizations adopt rapidly without mature hardening procedures. Securing these components requires treating them with the same rigorous governance traditionally applied to core network infrastructure.
Furthermore, CISA stresses that simply applying software updates is insufficient for systems that were exposed prior to patching. System administrators are advised to conduct retrospective audits to check for unauthorized tokens, spawned child processes, unexpected configuration changes, and abnormal outbound network communications.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment