On Wednesday, September 2, 2026, the Cybersecurity and Infrastructure Security Agency added seven known exploited vulnerabilities to its Known Exploited Vulnerabilities catalog after active exploitation, and attackers are using compromised software to open reverse shells, steal credentials, and deploy crypto miners, including against AI infrastructure, with CVSS ratings from 6.5 to 10.0.
Federal officials confirmed all seven are actively exploited in live attacks, and two are rated CVSS 10.0 — Kestra’s OS command injection (CVE-2026-49869) and SonicWall SMA1000 SSRF (CVE-2026-83548) — with affected versions and patches listed such as Starlette below 1.0.1, Kestra below 1.0.45 or 1.3.21, and LiteLLM below 1.84.0.
The catalog addition notably included two critical-severity AI-infrastructure flaws — Kestra’s command injection and Berri LiteLLM’s MCP auth bypass — alongside the other enterprise bugs, reflecting the agency’s warning that crypto miners and reverse shells are being deployed against AI systems.
The split patch deadline under BOD 26-04 puts most federal agencies on a three-day turnaround from the September 2 update, while the Starlette and LiteLLM flaws get until September 16.
What makes the list notable is the co-occurrence of two CVSS 10.0 entries with lower-severity request-smuggling and auth-bypass bugs, all confirmed live-exploited rather than theoretical, which compresses the defensive window for teams running any of the named products.
For defenders, the practical takeaway is version-specific: Starlette deployments below 1.0.1, Kestra below 1.0.45 or 1.3.21, and LiteLLM below 1.84.0 are explicitly called out as affected, and the federal timeline sets the outer bound for action even for organizations outside the FCEB mandate.