What CISA Added to the KEV Catalog on September 2
The US Cybersecurity and Infrastructure Security Agency added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2, 2026.
CISA's advisory named the affected products directly: SonicWall SMA1000, Sangoma Switchvox, Starlette, Kestra OSS, BerriAI LiteLLM and JFrog Artifactory. Each entry means CISA has confirmed exploitation in the wild, not a theoretical risk flagged by researchers.
Why the SonicWall Flaws Deserve Your Attention First
Two of the seven vulnerabilities affect SonicWall's SMA1000, a remote-access VPN appliance that sits at the network edge of many organizations.
CVE-2026-83548 is a server-side request forgery flaw, and CVE-2026-83549 is an OS command injection flaw; both let an attacker who reaches the appliance's management interface act against internal systems behind it. SMA1000 is widely deployed by small and mid-market European companies as the front door for remote staff, often run by lean IT teams without a dedicated security operations center watching it around the clock.
The Full List: Seven CVEs, Seven Products
CISA's advisory named seven distinct vulnerabilities across seven different products, and the table below lists each one alongside its vulnerability type.
| CVE | Product | Vulnerability type |
|---|---|---|
| CVE-2026-83548 | SonicWall SMA1000 | SSRF (server-side request forgery) |
| CVE-2026-83549 | SonicWall SMA1000 | OS command injection |
| CVE-2026-9586 | Sangoma Switchvox | SQL injection |
| CVE-2026-48710 | Starlette | Request smuggling |
| CVE-2026-49869 | Kestra OSS | Command injection |
| CVE-2026-59822 | BerriAI LiteLLM | Authentication bypass |
| CVE-2026-82329 | JFrog Artifactory | Authentication bypass |
All seven share one property that matters more than their individual severity scores: CISA states each has been observed under active exploitation, not merely proven exploitable in a lab.
No Legal Deadline for EU Companies - That Is the Point
CISA's Binding Operational Directive 26-04 sets a remediation deadline that applies only to US federal civilian agencies, not to European businesses.
An EU company running SonicWall SMA1000 has no NIS2 trigger tied specifically to this KEV addition either, so nothing forces a patch cycle by law. That gap is exactly what makes the KEV catalog worth reading anyway: the designation is a confirmed-exploitation signal security teams worldwide track regardless of which jurisdiction's deadline attaches to it, and attackers do not check which country's regulation applies before they scan for an exposed appliance.
What to Actually Do Monday Morning
An IT team running SonicWall SMA1000 for remote access should check that device against CISA's advisory before doing anything else this week.
Three steps in order: confirm whether SMA1000 is in use anywhere in the environment, including instances a remote team set up without central IT's knowledge; apply SonicWall's patch for both CVEs immediately, or take the management interface off the public internet if a patch cannot be applied today; and review access logs for the appliance for signs the two flaws were already used before the patch went in. Not being legally required to patch is irrelevant to whether the appliance gets breached.
LiteLLM: The Flaw That Reaches Beyond VPN Appliances
CVE-2026-59822 affects BerriAI's LiteLLM, an authentication bypass flaw in software that functions as a self-hosted gateway in front of large language models.
LiteLLM is an increasingly common piece of EU enterprise AI infrastructure, used to route, log and control access to LLM calls across a company's own applications. A team running a self-hosted LLM gateway should check whether LiteLLM is part of that stack and patch it with the same urgency as the SonicWall flaws, since an authentication bypass on a gateway sitting in front of internal AI tooling is exactly the kind of access attackers now go looking for.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Exploited Weeks Before PaperCut Ever Patched | If You Run Zimbra, August 21 Changed Your Risk



