CiberLATAMbywhalemate

CISA adds 7 critical flaws to KEV

CISA added seven vulnerabilities to the KEV, including active exploitation in SonicWall SMA 1000, Kestra OSS, LiteLLM and Sangoma Switchvox.

Whalemate Labs · AI-assisted researchPublished:3 min read

CISA added seven vulnerabilities to its KEV catalog, including flaws with active exploitation in SonicWall SMA 1000, Kestra OSS, BerriAI LiteLLM and Sangoma Switchvox. In parallel, technical analyses said the SonicWall CVEs form a chain of at least three flaws and affect only the SMA1000 series.

CISA has added seven vulnerabilities to its KEV catalog, and the cited advisory identifies active exploitation in SonicWall SMA 1000, Kestra OSS, BerriAI LiteLLM and Sangoma Switchvox. Other intelligence reports also added CVE-2026-67277 to the list and recorded real-world attacks against MikroTik RouterOS, while attention on SonicWall focused on a chain of flaws that ends in remote code execution with root privileges.

What happened with SonicWall SMA 1000?

CVE-2026-83548 was described by independent technical analysis as a pre-authentication SSRF in the Appliance Work Place interface, with a CVSS score of 10.0, and was exploited in practice as part of a chain to achieve RCE without credentials. SonicWall has already published its official advisory, acknowledged active exploitation in the wild of CVE-2026-83548 and CVE-2026-83549, and said patches are available.

Researchers said the exploitation chain has at least three stages. First, the SSRF in CVE-2026-83548 lets the appliance act as an unintended internal proxy. Then another bug enables low-priority CouchDB read and write access. Finally, an additional command injection in cmsSnmpTrap escalates the attack to RCE with root privileges.

Which devices are affected?

Technical coverage says only the SMA1000 series, in its 6210, 7210, 8200v, physical and virtual variants, is affected by CVE-2026-83548 and CVE-2026-83549. The SMA-100 series and the built-in SSL VPN in SonicWall firewalls are not affected, a key distinction for inventory and response planning at companies and operators.

The advisories also specify the exposed branches and the fixed ones. Versions 12.4.3-03453 and earlier, and 12.5.0-02835 and earlier, are considered vulnerable. As mitigation, 12.4.3-03526 and 12.5.0-02952 are recommended, versions that were also reinforced by external intelligence repositories calling for the hotfixes to be applied immediately.

Why is this flaw so concerning for defenders?

The severity of CVE-2026-83548 lies in its ability to turn the appliance into an internal proxy for reaching resources and management consoles not exposed to the internet. Quasa warned that this pattern makes it easier to trigger CVE-2026-83549 for RCE, which is especially sensitive in distributed corporate networks such as those in the region.

Secure in Seconds added that, in remote branches and country offices, direct exposure of the Work Place interface to the internet is the main risk factor. That analysis recommended a maximum patching window of 48 hours and reviewing logs to detect possible prior compromise.

What other flaws entered the KEV?

Alongside SonicWall, CISA added CVE-2026-49869 in Kestra OSS, CVE-2026-59822 in BerriAI LiteLLM and CVE-2026-9586 in Sangoma Switchvox, all mentioned in the advisory as part of the seven additions. At the same time, CISA also added CVE-2026-67277 to its catalog, and CERT Polska observed real attacks starting at least on 2026-09-02.

Later bulletins emphasized that CVE-2026-83548 and CVE-2026-83549 were added to the KEV together and that both are confirmed zero-days exploited in the real world. In that context, SonicWall rises on urgent patching lists, alongside the other products already in the catalog.

Sources

View all