CISA KEV multi-vulnerability exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
CISA's KEV list gained seven exploited flaws, signaling active abuse across SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra OSS, and LiteLLM. Attackers were observed weaponizing some of the vulnerabilities to deploy reverse shells, mint admin tokens, and install cryptocurrency miners. The wave also reached AI infrastructure and exposed systems that operators were told to patch on an accelerated schedule.
Related Happenings
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
PaperCut emergency patches for public-facing NG/MF servers
Security Patch Release
H score51
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...
PaperCut emergency patches for public-facing NG/MF servers
Security Patch ReleaseAbout this happening: PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.
Iranian threat actors' Water and Wastewater Systems PLC targeting campaign
Campaign
H score33
First: 26.08.2026 14:29
Last: 26.08.2026 14:29
Sources 1
About this happening:
A campaign tied to Iranian threat actors targeted over 100 internet-exposed water systems in July 2026, signaling a broad operation against critical OT environment...
Iranian threat actors' Water and Wastewater Systems PLC targeting campaign
CampaignAbout this happening: A campaign tied to Iranian threat actors targeted over 100 internet-exposed water systems in July 2026, signaling a broad operation against critical OT environment...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
Campaign
H score17
First: 19.08.2026 20:50
Last: 19.08.2026 20:50
Sources 1
About this happening:
The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure
CampaignAbout this happening: The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign...
U.S. agencies expand PLC-targeting warning and guidance
Public Sector Action
H score22
First: 29.07.2026 16:48
Last: 29.07.2026 16:48
Sources 1
About this happening:
U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk...
U.S. agencies expand PLC-targeting warning and guidance
Public Sector ActionAbout this happening: U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk...
Timeline
-
03.09.2026 08:19 2 articles · 13d ago
CISA adds seven exploited flaws to the KEV catalog
Initial DisclosureCISA added seven vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog after active exploitation was reported across SonicWall SMA 1000 Appliances, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM/LiteLLM. Reported activity included reverse shells, admin-token abuse, XMRig delivery, persistence, Docker container discovery, and LiteLLM-backed PostgreSQL data access; Federal Civilian Executive Branch agencies were told to patch most flaws by September 5, 2026, with CVE-2026-48710 and CVE-2026-59822 due by September 16, 2026.
Show sources
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — thehackernews.com — 03.09.2026 08:19
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — thehackernews.com — 03.09.2026 08:19