Search
Find merged stories by title or summary.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
CVE-2026-49869 - Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
You've reached the end of current stories for this search.
