← Knowledge Center
Advisory CVE-2026-9586, CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549

CISA Adds Seven Actively Exploited Flaws to KEV, Including Auth Bypasses

CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Two of the additions are directly identity/access-relevant: CVE-2026-59822, an improper authentication flaw in BerriAI’s LiteLLM, and CVE-2026-82329, an improper authentication flaw in JFrog Artifactory. Both could allow attackers to bypass authentication controls and gain unauthorized access to these services.

The remaining additions cover SQL injection (Sangoma Switchvox), HTTP request/response smuggling (Starlette), OS command injection (Kestra OSS and SonicWall SMA1000), and SSRF (SonicWall SMA1000). While not all are strictly credential-related, authentication bypasses in artifact repositories and AI gateway proxies can expose secrets, tokens, and downstream systems.

What to take away: Federal agencies under BOD 26-04 must prioritize remediation, but any organization running LiteLLM or Artifactory should patch immediately—improper authentication flaws are frequently chained to broader lateral movement and credential theft.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.