Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV multi-vulnerability exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 59
1 unique sources, 1 articles

Summary

Hide ▲

CISA's KEV list gained seven exploited flaws, signaling active abuse across SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra OSS, and LiteLLM. Attackers were observed weaponizing some of the vulnerabilities to deploy reverse shells, mint admin tokens, and install cryptocurrency miners. The wave also reached AI infrastructure and exposed systems that operators were told to patch on an accelerated schedule.

Related Happenings

Iranian threat actors' Water and Wastewater Systems PLC targeting campaign

Campaign
H score33 First: 26.08.2026 14:29 Last: 26.08.2026 14:29 Sources 1

About this happening: A campaign tied to Iranian threat actors targeted over 100 internet-exposed water systems in July 2026, signaling a broad operation against critical OT environment...

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
H score17 First: 19.08.2026 20:50 Last: 19.08.2026 20:50 Sources 1

About this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...

U.S. agencies expand PLC-targeting warning and guidance

Public Sector Action
H score22 First: 29.07.2026 16:48 Last: 29.07.2026 16:48 Sources 1

About this happening: U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

How related: Pursuant to "Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk," Federal Civilian Executive Branch (FCEB) agencies are recommended to apply patches for all the vulnerabilities, barring CVE-2026-48710 and CVE-2026-59822, by September 5, 2026.

About this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...

Timeline

  1. 03.09.2026 08:19 2 articles · 2h ago

    CISA adds seven exploited flaws to the KEV catalog

    Initial Disclosure

    CISA added seven vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog after active exploitation was reported across SonicWall SMA 1000 Appliances, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM/LiteLLM. Reported activity included reverse shells, admin-token abuse, XMRig delivery, persistence, Docker container discovery, and LiteLLM-backed PostgreSQL data access; Federal Civilian Executive Branch agencies were told to patch most flaws by September 5, 2026, with CVE-2026-48710 and CVE-2026-59822 due by September 16, 2026.

    Show sources