>samit_hota
Back to security news

Security News · SN-2026-436

CRITICALCVE-2026-83548OPEN

CISA Adds 7 Exploited Flaws to KEV Catalog as Attackers Target AI Infra

Affected: SonicWall SMA 1000 · Berri LiteLLM · Kestra OSS · JFrog Artifactory · Sangoma Switchvox · Kludex Starlette

Samit Hota·
#news#vulnerability-disclosure#cisa

Threat actors are aggressively expanding their focus from traditional edge appliances to emerging artificial intelligence management stacks, prompting federal cyber authorities to issue urgent update directives. The Cybersecurity and Infrastructure Security Agency (CISA) added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after observing real-world weaponization ranging from remote command execution on perimeter appliances to persistent API key theft in large language model (LLM) orchestration environments. Central to the catalog additions is a critical SonicWall SMA 1000 vulnerability (CVE-2026-83548), alongside flaws impacting AI tools like Berri LiteLLM and Kestra OSS.

SonicWall SMA 1000 Vulnerabilities Drive Perimeter Attacks

SonicWall confirmed active exploitation in the wild targeting its SMA 1000 series appliances, involving a combination of Server-Side Request Forgery (SSRF) and post-authentication command injection. The most severe issue, CVE-2026-83548 (CVSS 10.0), allows a remote, unauthenticated attacker to access restricted management functionality and perform unauthorized actions across the appliance.

While its current Exploit Prediction Scoring System (EPSS) rating sits at a modest 0.27% (18.2th percentile), the technical exposure defined by its CVSS v3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) underscores extreme operational risk: zero authentication required, network-accessible, low attack complexity, and a scope change (S:C) that permits attackers to pivot beyond the boundary interface into underlying system components.

When paired with CVE-2026-83549 (CVSS 7.8)—a post-authentication OS command injection flaw—an attacker possessing administrator rights can achieve full remote code execution on the underlying operating system. SonicWall’s internal investigations confirmed that adversaries have actively leveraged this pair to establish operational footholds on affected appliances.

AI Infrastructure and Gateway Abuse

Beyond classic edge appliances, threat telemetry reveals a concerted shift toward compromising AI application stack components. Attackers are prioritizing AI gateways, orchestration frameworks, and model context protocol (MCP) endpoints to harvest high-value credentials and hijack host compute resources.

  • Berri LiteLLM & Kludex Starlette Chain: Adversaries associated with the Qilin (Agenda) ransomware group have been observed chaining an HTTP request/response smuggling flaw in Kludex Starlette (CVE-2026-48710, CVSS 6.5) with a LiteLLM authentication bypass (CVE-2026-42271, CVSS 8.7). By prepending paths into reconstructed host headers, attackers bypass authentication barriers and execute arbitrary code on vulnerable LiteLLM deployments. Concurrently, honeypots tracked by Wiz recorded active scanning against LiteLLM’s MCP Streamable HTTP endpoint (CVE-2026-59822, CVSS 8.8), where unauthenticated actors establish sessions using arbitrary Bearer tokens.
  • Database Exfiltration and Cryptomining: In documented LiteLLM compromises, attackers drop XMRig cryptocurrency miners via ELF binaries after terminating competing miner processes. Beyond resource hijacking, threat actors query the underlying PostgreSQL database tier to extract sensitive records from tables such as LiteLLM_ProxyModelTable and LiteLLM_VerificationToken. This allows adversaries to steal upstream provider API keys, proxy virtual tokens, and model endpoints. Operational persistence is established by appending public keys to ~/.ssh/authorized_keys.
  • Kestra OSS Workflow Exploitation: Microsoft documented exploitation of CVE-2026-49869 (CVSS 10.0), an unauthenticated OS command injection flaw in Kestra OSS. Threat actors create unauthorized workflows to drop reverse shells, mount host Docker sockets for container discovery, deploy cryptominers, and harvest local data. To evade detection, attackers encode exfiltrated file outputs directly into Kestra’s native key-value storage interface rather than leaving standalone staging files on disk.
  • RAGFlow Exposure: Similar key harvesting campaigns have targeted exposed RAGFlow instances using a cluster of vulnerabilities (CVE-2026-45312, CVE-2026-28797, CVE-2026-24770, CVE-2025-68700, and CVE-2025-69286) to extract LLM provider key material and persist within AI control planes.

Enterprise and Developer Tooling Targeted

In parallel with AI infra attacks, threat research groups Horizon3.ai and watchTowr reported active exploitation of enterprise service software:

  • Sangoma Switchvox (CVE-2026-9586, CVSS 9.3): An unauthenticated SQL injection vulnerability allowing attackers to execute arbitrary SQL commands against the backend PostgreSQL database using a single crafted request, achieving remote code execution.
  • JFrog Artifactory (CVE-2026-82329, CVSS 9.8): An improper authentication flaw under default configurations enabling unauthenticated network attackers to acquire administrative privileges. Attackers weaponized this flaw to mint admin tokens and perform deep directory enumeration across groups, user accounts, and federated identity topologies.

Remediation Requirements

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies must complete remediation according to the following timeline, which serves as an urgent benchmark for private enterprises:

  1. SonicWall SMA 1000 Series: Immediately upgrade SMA 6210, SMA 7210, and SMA 8200v appliances to firmware version 12.4.3-03526 or 12.5.0-02952 (or later) per SonicWall Advisory SNWLID-2026-0016. Federal compliance deadline is September 5, 2026.
  2. Kestra OSS, Sangoma Switchvox, and JFrog Artifactory: Apply vendor patches for CVE-2026-49869, CVE-2026-9586, and CVE-2026-82329 by September 5, 2026.
  3. Starlette and LiteLLM Frameworks: Update Kludex Starlette and Berri LiteLLM deployments to patch CVE-2026-48710 and CVE-2026-59822 by September 16, 2026.

Security teams managing AI workloads should audit external exposure of proxy layers, restrict access to underlying database tiers storing model API credentials, disable unauthenticated access to Docker Unix sockets, and inspect ~/.ssh/authorized_keys across hosts running orchestration middleware.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call