official data

CISA KEV: seven actively exploited CVEs include LiteLLM AI gateway and SonicWall SMA1000

Lane: aiWashington, District of Columbia, USA

On 2 September 2026, the Cybersecurity and Infrastructure Security Agency announced it had added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The list includes CVE-2026-59822, BerriAI LiteLLM Improper Authentication — an AI gateway / LLM proxy product — alongside Sangoma Switchvox, Kludex Starlette, Kestra OSS, JFrog Artifactory, and two SonicWall SMA1000 appliance flaws (CVE-2026-83548 server-side request forgery and CVE-2026-83549 OS command injection). CISA reiterated that Binding Operational Directive 26-04 establishes vulnerability management requirements for Federal Civilian Executive Branch agencies, reinforces KEV prioritization for high-risk publicly exposed assets, and sets basic expectations for checking whether threat actors compromised a system before a patch was applied. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize KEV remediation.

Estimated centroid near Washington, DC (~38.9072°N, 77.0369°W), CISA headquarters context for the KEV catalog alert. Source map

Key facts

Alert date
September 2, 2026 — seven CVEs added to KEV Catalog
AI-relevant CVE
CVE-2026-59822 BerriAI LiteLLM Improper Authentication
Remote-access CVEs
CVE-2026-83548 SonicWall SMA1000 SSRF; CVE-2026-83549 SonicWall SMA1000 OS Command Injection
Other CVEs in drop
Sangoma Switchvox SQLi; Kludex Starlette request/response smuggling; Kestra OSS OS command injection; JFrog Artifactory improper authentication
Policy hook
BOD 26-04 risk-based KEV prioritization for FCEB; pre-patch compromise check expectations
Audience beyond FCEB
CISA encourages all organizations to prioritize KEV remediation

Note

Official product: CISA alert dated 2 September 2026 plus the KEV Catalog listing. Doom Signals does not invent exploit counts, victim sectors, or ransomware attribution beyond CISA’s “evidence of active exploitation” framing for catalog inclusion.

  • Source: CISA KEV alert, 2 Sep 2026
  • Place pin: Washington, DC (CISA)
  • Dedup: not PaperCut KEV or OT outage playbook

Why it matters

A same-day CISA KEV drop that places an AI gateway (LiteLLM) and widely deployed remote-access appliances under active-exploitation status is a concrete AI/cyber governance signal — distinct from the PaperCut KEV and OT outage communications playbook already filed.

Sources

Official data. Not a forecast.

← Daily board