official data
CISA KEV: seven actively exploited CVEs include LiteLLM AI gateway and SonicWall SMA1000
On 2 September 2026, the Cybersecurity and Infrastructure Security Agency announced it had added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The list includes CVE-2026-59822, BerriAI LiteLLM Improper Authentication — an AI gateway / LLM proxy product — alongside Sangoma Switchvox, Kludex Starlette, Kestra OSS, JFrog Artifactory, and two SonicWall SMA1000 appliance flaws (CVE-2026-83548 server-side request forgery and CVE-2026-83549 OS command injection). CISA reiterated that Binding Operational Directive 26-04 establishes vulnerability management requirements for Federal Civilian Executive Branch agencies, reinforces KEV prioritization for high-risk publicly exposed assets, and sets basic expectations for checking whether threat actors compromised a system before a patch was applied. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize KEV remediation.
Key facts
- Alert date
- September 2, 2026 — seven CVEs added to KEV Catalog
- AI-relevant CVE
- CVE-2026-59822 BerriAI LiteLLM Improper Authentication
- Remote-access CVEs
- CVE-2026-83548 SonicWall SMA1000 SSRF; CVE-2026-83549 SonicWall SMA1000 OS Command Injection
- Other CVEs in drop
- Sangoma Switchvox SQLi; Kludex Starlette request/response smuggling; Kestra OSS OS command injection; JFrog Artifactory improper authentication
- Policy hook
- BOD 26-04 risk-based KEV prioritization for FCEB; pre-patch compromise check expectations
- Audience beyond FCEB
- CISA encourages all organizations to prioritize KEV remediation
Note
Official product: CISA alert dated 2 September 2026 plus the KEV Catalog listing. Doom Signals does not invent exploit counts, victim sectors, or ransomware attribution beyond CISA’s “evidence of active exploitation” framing for catalog inclusion.
- Source: CISA KEV alert, 2 Sep 2026
- Place pin: Washington, DC (CISA)
- Dedup: not PaperCut KEV or OT outage playbook
Why it matters
A same-day CISA KEV drop that places an AI gateway (LiteLLM) and widely deployed remote-access appliances under active-exploitation status is a concrete AI/cyber governance signal — distinct from the PaperCut KEV and OT outage communications playbook already filed.
Sources
Official data. Not a forecast.